RHSA-2024:2693MediumCVSS 7.5
Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP4 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2024-2004 — curl: Usage of disabled protocol CVE-2024-2379 — curl: QUIC certificate check bypass with wolfSSL CVE-2024-2398 — curl: HTTP/2 push headers memory-leak CVE-2024-2466 — curl: TLS certificate check bypass with mbedTLS CVE-2024-27316 — httpd: CONTINUATION frames DoS CVE-2024-28182 — nghttp2: CONTINUATION frames DoS
🎯 Affected products78
- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-curl-0:8.7.1-2.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-curl-0:8.7.1-2.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-curl-0:8.7.1-2.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-curl-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-curl-debuginfo-0:8.7.1-2.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-curl-debuginfo-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-0:2.4.57-10.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-0:2.4.57-10.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-debuginfo-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-debuginfo-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-devel-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-devel-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-manual-0:2.4.57-10.el7jbcs.noarch as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-manual-0:2.4.57-10.el8jbcs.noarch as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-selinux-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-selinux-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-tools-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-tools-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-tools-debuginfo-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-libcurl-0:8.7.1-2.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-libcurl-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-libcurl-debuginfo-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-libcurl-devel-0:8.7.1-2.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-libcurl-devel-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-mod_http2-0:1.15.19-37.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-mod_http2-0:1.15.19-37.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- +48 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2024:2693
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_core_services/2.4.57/html/red_hat_jboss_core_services_apache_http_server_2.4.57_service_pack_4_release_notes
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268277
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268639
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270498
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270500
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2693.json