RHSA-2022:1390HighCVSS 8.6

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP11 security update

Published
April 20, 2022
Last Modified
August 7, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2021-3516 — libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c CVE-2021-3517 — libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c CVE-2021-3518 — libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c CVE-2021-3537 — libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode CVE-2021-3541 — libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms CVE-2022-0778 — openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates CVE-2022-22720 — httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling CVE-2022-23308 — libxml2: Use-after-free of ID and IDREF attributes

🎯 Affected products1

  • Text-Only JBCS

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: This flaw can be mitigated by not using xmllint with the --html and --push options together. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: There are currently no known mitigations for this issue.

🔗 References (11)