RHSA-2022:0146MediumCVSS 7.8

Red Hat Security Advisory: EAP XP 2 security update to CVE fixes in the EAP 7.3.x base

Published
January 17, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2021-3629 — undertow: potential security issue in flow control over HTTP/2 may lead to DOS CVE-2021-3642 — wildfly-elytron: possible timing attack in ScramServer CVE-2021-3717 — wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users CVE-2021-20289 — resteasy: Error message exposes endpoint class information CVE-2021-37714 — jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck CVE-2021-40690 — xml-security: XPath Transform abuse allows for information disclosure

🎯 Affected products1

  • Red Hat EAP-XP 2 via EAP 7.3.x base

✅ Remediation

This advisory is informational only. There are no code changes associated with it. No action is required.

🔗 References (12)