CVE-2021-20318: High severity jboss enterprise application platform vulnerability
It was found that HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
Other sources
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-20318?
CVE-2021-20318 is a vulnerability in the HornetQ component of Artemis in EAP 7 that allows a remote attacker to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
What is the severity of CVE-2021-20318?
CVE-2021-20318 has a severity rating of 7.2, which is classified as high.
Which software versions are affected by CVE-2021-20318?
CVE-2021-20318 affects Redhat Jboss Enterprise Application Platform versions 7.3.9 and 7.4.0, as well as versions of eap7-hornetq up to 2.4.8-1.Final_redhat_00001.1.el8ea and 2.4.8-1.Final_redhat_00001.1.el7ea.
How can CVE-2021-20318 be fixed?
To fix CVE-2021-20318, it is recommended to update to version 2.4.8-1.Final_redhat_00001.1.el8ea or later for eap7-hornetq, or follow the guidance provided by Red Hat in their RHSA-2022:0404 advisory.
Where can I find more information about CVE-2021-20318?
More information about CVE-2021-20318 can be found on the CVE website, NIST National Vulnerability Database, Red Hat Bugzilla, and Red Hat Access website.