RHSA-2024:1317MediumCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP3 security update

Published
March 18, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2023-5678 — openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow CVE-2023-6710 — mod_cluster/mod_proxy_cluster: Stored Cross site Scripting CVE-2023-31122 — httpd: mod_macro: out-of-bounds read vulnerability CVE-2023-39615 — libxml2: crafted xml can cause global buffer overflow CVE-2023-46218 — curl: information disclosure by exploiting a mixed case flaw CVE-2023-46219 — curl: excessively long file name may lead to unknown HSTS status CVE-2024-25062 — libxml2: use-after-free in XMLReader

🎯 Affected products1

  • Text-Only JBCS

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Disabling mod_macro and restarting httpd or making sure the macros used are smaller than the required length to trigger this vulnerability will mitigate this flaw. Furthermore, it's unlikely that a very long macro with the length needed to trigger this issue is being used.

🔗 References (11)