Red Hat Security Advisory: Red Hat JBoss EAP 7.4.17 XP 4.0.2 security release
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-51775 — jose4j: denial of service via specially crafted JWE CVE-2024-6162 — undertow: url-encoded request path information can be broken on ajp-listener
🎯 Affected products1
- Red Hat JBoss Enterprise Application Platform Expansion Pack
✅ Remediation
Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, you can either switch to a different listener like the http-listener, or adjust the AJP listener configuration. By setting decode-url="false" on the AJP listener and configuring a separate URL decoding filter, you can prevent the path decoding errors. This adjustment ensures that each request is processed correctly without interference from concurrent requests.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:4386
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/red_hat_jboss_eap_xp_4.0.0_release_notes/
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html/jboss_eap_xp_4.0_upgrade_and_migration_guide/index
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/using_jboss_eap_xp_4.0.0/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266921
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4386.json