Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.11 Security update
🔗 CVE IDs covered (14)
📋 Description
CVE-2021-3859 — undertow: client side invocation timeout raised when calling over HTTP2 CVE-2021-4104 — log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender CVE-2022-23221 — h2: Loading of custom classes from remote servers through JNDI CVE-2022-23305 — log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender CVE-2022-23307 — log4j: Unsafe deserialization flaw in Chainsaw log viewer CVE-2022-34169 — OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) CVE-2022-41853 — hsqldb: Untrusted input may lead to RCE attack CVE-2022-46364 — CXF: SSRF Vulnerability CVE-2023-3171 — eap-7: heap exhaustion via deserialization CVE-2023-5685 — xnio: StackOverflowException when the chain of notifier states becomes problematically big CVE-2023-26464 — log4j1-socketappender: DoS via hashmap logging CVE-2023-39410 — apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK CVE-2024-28752 — cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding CVE-2024-47561 — apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2024:10207
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.3
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2010378
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031667
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041967
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044596
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108554
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136141
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182864
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213639
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2316116
- externalhttps://issues.redhat.com/browse/JBEAP-23025
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10207.json