RHSA-2024:2693MediumCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP4 security update

Published
May 7, 2024
Last Modified
August 18, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2024-2004 — curl: Usage of disabled protocol CVE-2024-2379 — curl: QUIC certificate check bypass with wolfSSL CVE-2024-2398 — curl: HTTP/2 push headers memory-leak CVE-2024-2466 — curl: TLS certificate check bypass with mbedTLS CVE-2024-27316 — httpd: CONTINUATION frames DoS CVE-2024-28182 — nghttp2: CONTINUATION frames DoS

🎯 Affected products78

  • Red Hat JBoss Core Services on RHEL 7 Server
  • Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-curl-0:8.7.1-2.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-curl-0:8.7.1-2.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-curl-0:8.7.1-2.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-curl-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-curl-debuginfo-0:8.7.1-2.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-curl-debuginfo-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-0:2.4.57-10.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-0:2.4.57-10.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-debuginfo-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-debuginfo-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-devel-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-devel-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-manual-0:2.4.57-10.el7jbcs.noarch as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-manual-0:2.4.57-10.el8jbcs.noarch as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-selinux-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-selinux-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-tools-0:2.4.57-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-httpd-tools-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-httpd-tools-debuginfo-0:2.4.57-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-libcurl-0:8.7.1-2.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-libcurl-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-libcurl-debuginfo-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-libcurl-devel-0:8.7.1-2.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-libcurl-devel-0:8.7.1-2.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
  • jbcs-httpd24-mod_http2-0:1.15.19-37.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • jbcs-httpd24-mod_http2-0:1.15.19-37.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
  • +48 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (10)