RHSA-2022:5893MediumCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.6 Security update

Published
August 3, 2022
Last Modified
September 17, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2021-44906 — minimist: prototype pollution CVE-2022-24823 — netty: world readable temporary file containing sensitive data CVE-2022-25647 — com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson

🎯 Affected products112

  • Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-apache-cxf-0:3.3.13-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-apache-cxf-0:3.3.13-1.redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-apache-cxf-rt-0:3.3.13-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-apache-cxf-services-0:3.3.13-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-apache-cxf-tools-0:3.3.13-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-glassfish-jsf-0:2.3.14-4.SP05_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-glassfish-jsf-0:2.3.14-4.SP05_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-gson-0:2.8.9-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-gson-0:2.8.9-1.redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-hal-console-0:3.3.13-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-hal-console-0:3.3.13-1.Final_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-hibernate-0:5.3.27-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-hibernate-0:5.3.27-1.Final_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-hibernate-core-0:5.3.27-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-hibernate-entitymanager-0:5.3.27-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-hibernate-envers-0:5.3.27-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-hibernate-java8-0:5.3.27-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-0:1.5.3-2.SP1_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-common-api-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-common-impl-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-common-spi-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-core-api-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-core-impl-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-deployers-common-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-jdbc-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-ironjacamar-validator-0:1.5.3-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-jackson-databind-0:2.12.6.1-2.redhat_00004.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • eap7-jackson-databind-0:2.12.6.1-2.redhat_00004.1.el8eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 8
  • +82 more not shown

✅ Remediation

Before applying this update, ensure all previously released errata relevant to your system have been applied. For details about how to apply this update, see: https://access.redhat.com/articles/11258 Workaround: As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.

🔗 References (33)