Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2022-24963 — apr: integer overflow/wraparound in apr_encode CVE-2022-36760 — httpd: mod_proxy_ajp: Possible request smuggling CVE-2022-37436 — httpd: mod_proxy: HTTP response splitting CVE-2022-48279 — mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass CVE-2023-24021 — modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to web application firewall bypass CVE-2023-27522 — httpd: mod_proxy_uwsgi HTTP response splitting CVE-2023-28319 — curl: use after free in SSH sha256 fingerprint check CVE-2023-28321 — curl: IDN wildcard match may lead to Improper Cerificate Validation CVE-2023-28322 — curl: more POST-after-PUT confusion
🎯 Affected products107
- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-0:1.7.0-8.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-0:1.7.0-8.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-0:1.7.0-8.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-0:1.7.0-8.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-debuginfo-0:1.7.0-8.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-debuginfo-0:1.7.0-8.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-devel-0:1.7.0-8.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-devel-0:1.7.0-8.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.1-102.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-0:1.6.1-102.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-0:1.6.1-102.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-debuginfo-0:1.6.1-102.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-debuginfo-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-devel-0:1.6.1-102.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-devel-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-ldap-0:1.6.1-102.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-ldap-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-ldap-debuginfo-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-mysql-0:1.6.1-102.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-mysql-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-mysql-debuginfo-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-nss-0:1.6.1-102.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-nss-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-nss-debuginfo-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-odbc-0:1.6.1-102.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-odbc-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-odbc-debuginfo-0:1.6.1-102.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- +77 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. It's recommended to update the affected packages as soon as an update is available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2023:4629
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2163615
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2163622
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2169465
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196778
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196793
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4629.json