Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.18 security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2024-29371 — jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression CVE-2025-9784 — undertow: Undertow MadeYouReset HTTP/2 DDoS Vulnerability CVE-2025-12543 — undertow-core: Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-23184 — org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files CVE-2025-23368 — org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI CVE-2025-66412 — angular: Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-1002 — io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files CVE-2026-24842 — node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check
🎯 Affected products37
- Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-apache-cxf-0:3.4.10-4.SP2_redhat_00004.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-apache-cxf-0:3.4.10-4.SP2_redhat_00004.1.el7eap.src as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-apache-cxf-rt-0:3.4.10-4.SP2_redhat_00004.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-apache-cxf-services-0:3.4.10-4.SP2_redhat_00004.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-apache-cxf-tools-0:3.4.10-4.SP2_redhat_00004.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-0:1.7.2-23.Final_redhat_00025.1.el7eap.src as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-cli-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-core-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-eap6.4-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-eap6.4-to-eap7.3-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-eap7.0-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-eap7.1-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-eap7.2-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-eap7.2-to-eap7.3-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-eap7.3-server-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly10.0-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly10.1-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly11.0-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly12.0-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly13.0-server-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly14.0-server-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly15.0-server-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly16.0-server-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly17.0-server-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly18.0-server-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly8.2-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-jboss-server-migration-wildfly9.0-0:1.7.2-23.Final_redhat_00025.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- eap7-undertow-0:2.0.41-8.SP9_redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server
- +7 more not shown
✅ Remediation
Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use, applicability, or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: The effectiveness of an attack will also be dependent on the complexity of the usernames and passwords defined for the target installation. Workaround: You could always manually sanitize user-controlled input or Disable or restrict dynamic SVG/MathML usage where possible in order to mitigate this flaw. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: To mitigate this vulnerability, consider disabling the static handler cache by configuring the StaticHandler instance with setCachingEnabled(false), for example: ~~~ StaticHandler staticHandler = StaticHandler.create().setCachingEnabled(false); ~~~
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:33371
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.3
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/index
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.3/html/7.3.0_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2339095
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2408784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2423194
- externalhttps://issues.redhat.com/browse/JBEAP-31703
- externalhttps://issues.redhat.com/browse/JBEAP-33004
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_33371.json