RHSA-2024:3385MediumCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss EAP 7.4.14 XP 4.0.2.GA security release

Published
May 28, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-3635 — okio: GzipSource class improper exception handling CVE-2023-26048 — jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() CVE-2023-26049 — jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform Expansion Pack

✅ Remediation

For details on how to apply this update, refer to the Using JBoss EAP XP 4 document: https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/using_jboss_eap_xp_4.0.0/index

🔗 References (12)