Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.2 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2021-3629 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS CVE-2021-3717 — wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-30129 — mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server CVE-2021-37714 — jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck CVE-2021-40690 — xml-security: XPath Transform abuse allows for information disclosure CVE-2022-1259 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)
🎯 Affected products1
- Red Hat JBoss Enterprise Application Platform 7
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update).
🔗 References (31)
- selfhttps://access.redhat.com/errata/RHSA-2021:4679
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=appplatform&version=7.4
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1977362
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991305
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011190
- externalhttps://issues.redhat.com/browse/JBEAP-21308
- externalhttps://issues.redhat.com/browse/JBEAP-22208
- externalhttps://issues.redhat.com/browse/JBEAP-22213
- externalhttps://issues.redhat.com/browse/JBEAP-22254
- externalhttps://issues.redhat.com/browse/JBEAP-22255
- externalhttps://issues.redhat.com/browse/JBEAP-22344
- externalhttps://issues.redhat.com/browse/JBEAP-22347
- externalhttps://issues.redhat.com/browse/JBEAP-22365
- externalhttps://issues.redhat.com/browse/JBEAP-22367
- externalhttps://issues.redhat.com/browse/JBEAP-22435
- externalhttps://issues.redhat.com/browse/JBEAP-22462
- externalhttps://issues.redhat.com/browse/JBEAP-22487
- externalhttps://issues.redhat.com/browse/JBEAP-22493
- externalhttps://issues.redhat.com/browse/JBEAP-22494
- externalhttps://issues.redhat.com/browse/JBEAP-22500
- externalhttps://issues.redhat.com/browse/JBEAP-22504
- externalhttps://issues.redhat.com/browse/JBEAP-22515
- externalhttps://issues.redhat.com/browse/JBEAP-22517
- externalhttps://issues.redhat.com/browse/JBEAP-22522
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4679.json