RHSA-2025:3453HighCVSS 8.1

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 security update

Published
April 2, 2025
Last Modified
September 1, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2023-52425 — expat: parsing large tokens can trigger a denial of service CVE-2024-5535 — openssl: SSL_select_next_proto buffer overread CVE-2024-24795 — httpd: HTTP Response Splitting in multiple modules CVE-2024-36387 — mod_http2: DoS by null pointer in websocket over HTTP/2 CVE-2024-45490 — libexpat: Negative Length Parsing Vulnerability in libexpat CVE-2024-56171 — libxml2: Use-After-Free in libxml2 CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2

🎯 Affected products1

  • Red Hat JBoss Core Services 2.4.62

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)