Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.9 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-48913 — org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability CVE-2025-55163 — netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability CVE-2025-58056 — netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
🎯 Affected products1
- Red Hat JBoss Enterprise Application Platform 8.0.9
✅ Remediation
Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce risk, deployments should restrict the allowed protocols in JMS configuration to trusted and expected values only. In particular, disallow the use of rmi:// and ldap:// URLs, which could be abused for remote class loading and code execution. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, enforce strict RFC compliance on all front-end proxies and load balancers so that lone LF characters in chunk extensions are rejected or normalized before being forwarded. Additionally, configure input validation at the application or proxy layer to block malformed chunked requests, ensuring consistent parsing across all components in the request path.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2025:17318
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.0
- externalhttps://access.redhat.com/articles/7131053
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2387221
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2388252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392996
- externalhttps://issues.redhat.com/browse/JBEAP-30702
- externalhttps://issues.redhat.com/browse/JBEAP-30733
- externalhttps://issues.redhat.com/browse/JBEAP-30757
- externalhttps://issues.redhat.com/browse/JBEAP-30758
- externalhttps://issues.redhat.com/browse/JBEAP-30760
- externalhttps://issues.redhat.com/browse/JBEAP-30762
- externalhttps://issues.redhat.com/browse/JBEAP-30886
- externalhttps://issues.redhat.com/browse/JBEAP-30888
- externalhttps://issues.redhat.com/browse/JBEAP-30890
- externalhttps://issues.redhat.com/browse/JBEAP-30917
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_17318.json