RHSA-2023:4507HighCVSS 7.5
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2021-46877 — jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode CVE-2023-1436 — jettison: Uncontrolled Recursion in JSONArray CVE-2023-3223 — undertow: OutOfMemoryError due to @MultipartConfig handling
🎯 Affected products68
- Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-0:2.16.0-12.redhat_00048.1.el9eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-cli-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-commons-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-core-client-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-dto-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-hornetq-protocol-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-hqclient-protocol-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-jdbc-store-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-jms-client-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-jms-server-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-journal-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-ra-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-selector-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-server-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-service-extensions-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-activemq-artemis-tools-0:2.16.0-12.redhat_00048.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-glassfish-jaf-0:1.2.2-2.redhat_00002.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-glassfish-jaf-0:1.2.2-2.redhat_00002.1.el9eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-glassfish-javamail-0:1.6.7-2.redhat_00003.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-glassfish-javamail-0:1.6.7-2.redhat_00003.1.el9eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-hal-console-0:3.3.18-1.Final_redhat_00001.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-hal-console-0:3.3.18-1.Final_redhat_00001.1.el9eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-hibernate-0:5.3.30-1.Final_redhat_00001.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-hibernate-0:5.3.30-1.Final_redhat_00001.1.el9eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-hibernate-core-0:5.3.30-1.Final_redhat_00001.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-hibernate-envers-0:5.3.30-1.Final_redhat_00001.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-insights-java-client-0:1.0.9-1.redhat_00001.1.el9eap.noarch as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- eap7-insights-java-client-0:1.0.9-1.redhat_00001.1.el9eap.src as a component of Red Hat JBoss EAP 7.4 for RHEL 9
- +38 more not shown
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (29)
- selfhttps://access.redhat.com/errata/RHSA-2023:4507
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209689
- externalhttps://issues.redhat.com/browse/JBEAP-24711
- externalhttps://issues.redhat.com/browse/JBEAP-24722
- externalhttps://issues.redhat.com/browse/JBEAP-24744
- externalhttps://issues.redhat.com/browse/JBEAP-24745
- externalhttps://issues.redhat.com/browse/JBEAP-24790
- externalhttps://issues.redhat.com/browse/JBEAP-24808
- externalhttps://issues.redhat.com/browse/JBEAP-24819
- externalhttps://issues.redhat.com/browse/JBEAP-24820
- externalhttps://issues.redhat.com/browse/JBEAP-24821
- externalhttps://issues.redhat.com/browse/JBEAP-24822
- externalhttps://issues.redhat.com/browse/JBEAP-24831
- externalhttps://issues.redhat.com/browse/JBEAP-24832
- externalhttps://issues.redhat.com/browse/JBEAP-24835
- externalhttps://issues.redhat.com/browse/JBEAP-24836
- externalhttps://issues.redhat.com/browse/JBEAP-24858
- externalhttps://issues.redhat.com/browse/JBEAP-24973
- externalhttps://issues.redhat.com/browse/JBEAP-25004
- externalhttps://issues.redhat.com/browse/JBEAP-25085
- externalhttps://issues.redhat.com/browse/JBEAP-25086
- externalhttps://issues.redhat.com/browse/JBEAP-25204
- externalhttps://issues.redhat.com/browse/JBEAP-25205
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4507.json