RHSA-2022:8840MediumCVSS 9.8

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.51 SP1 security update

Published
December 8, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (17)

📋 Description

CVE-2022-1292 — openssl: c_rehash script allows command injection CVE-2022-2068 — openssl: the c_rehash script allows command injection CVE-2022-22721 — httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody CVE-2022-23943 — httpd: mod_sed: Read/write beyond bounds CVE-2022-26377 — httpd: mod_proxy_ajp: Possible request smuggling CVE-2022-27781 — curl: CERTINFO never-ending busy-loop CVE-2022-28614 — httpd: Out-of-bounds read via ap_rwrite() CVE-2022-28615 — httpd: Out-of-bounds read in ap_strcmp_match() CVE-2022-30522 — httpd: mod_sed: DoS vulnerability CVE-2022-31813 — httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism CVE-2022-32206 — curl: HTTP compression denial of service CVE-2022-32207 — curl: Unpreserved file permissions CVE-2022-32208 — curl: FTP-KRB bad message verification CVE-2022-32221 — curl: POST following PUT confusion CVE-2022-35252 — curl: Incorrect handling of control code characters in cookies CVE-2022-42915 — curl: HTTP proxy double-free CVE-2022-42916 — curl: HSTS bypass via IDN

🎯 Affected products134

  • Red Hat JBoss Core Services on RHEL 7 Server
  • Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-0:1.6.1-99.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-0:1.6.1-99.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-debuginfo-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-debuginfo-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-devel-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-devel-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-ldap-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-ldap-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-ldap-debuginfo-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-mysql-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-mysql-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-mysql-debuginfo-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-nss-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-nss-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-nss-debuginfo-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-odbc-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-odbc-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-odbc-debuginfo-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-openssl-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-openssl-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-openssl-debuginfo-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-pgsql-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-pgsql-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-pgsql-debuginfo-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-apr-util-sqlite-0:1.6.1-99.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-apr-util-sqlite-0:1.6.1-99.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • +104 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Applications using the APR libraries, such as httpd, must be restarted for this update to take effect. After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: As mentioned in the upstream security advisory, use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Workaround: As mentioned in the upstream security advisory, use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command-line tool. Workaround: Set the LimitXMLRequestBody option to a value smaller than 350MB. Setting it to 0 is not recommended as it will use a hard limit (depending on 32bit or 64bit systems) which may result in an overall system out-of-memory. The default configuration is not vulnerable to this flaw, see the statement above. Workaround: Disabling mod_sed and restarting httpd will mitigate this flaw. See https://access.redhat.com/articles/10649 for more information. Workaround: Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw. Workaround: Disabling mod_sed and restarting httpd will mitigate this flaw. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (20)