RHSA-2021:4679MediumCVSS 7.8

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.2 security update

Published
November 15, 2021
Last Modified
August 10, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2021-3629 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS CVE-2021-3717 — wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-30129 — mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server CVE-2021-37714 — jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck CVE-2021-40690 — xml-security: XPath Transform abuse allows for information disclosure CVE-2022-1259 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform 7

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (31)