First published: Wed Apr 25 2018(Updated: )
The eap7-jboss-ec2-eap packages provide scripts for Red Hat JBoss Enterprise Application Platform running on the Amazon Web Services (AWS) Elastic Compute Cloud (EC2).<br>With this update, the eap7-jboss-ec2-eap package has been updated to ensure<br>compatibility with Red Hat JBoss Enterprise Application Platform 7.1.2.<br>Refer to the JBoss Enterprise Application Platform 7.1 Release Notes, linked to in the References section, for information on the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix</li> of CVE-2016-4993) (CVE-2018-1067)<br><li> wildfly-undertow: undertow: Path traversal in ServletResourceManager class</li> (CVE-2018-1047)<br><li> slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088)</li> Red Hat would like to thank Ammarit Thongthua and Nattakit Intarasorn (Deloitte Thailand Pentest team) for reporting CVE-2018-1067, and Chris McCown for reporting CVE-2018-8088.<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-jboss-ec2-eap | <7.1.2-1.GA_redhat_1.ep7.el7 | 7.1.2-1.GA_redhat_1.ep7.el7 |
redhat/eap7-jboss-ec2-eap | <7.1.2-1.GA_redhat_1.ep7.el7 | 7.1.2-1.GA_redhat_1.ep7.el7 |
redhat/eap7-jboss-ec2-eap-samples | <7.1.2-1.GA_redhat_1.ep7.el7 | 7.1.2-1.GA_redhat_1.ep7.el7 |
redhat/eap7-jboss-ec2-eap | <7.1.2-1.GA_redhat_1.ep7.el6 | 7.1.2-1.GA_redhat_1.ep7.el6 |
redhat/eap7-jboss-ec2-eap | <7.1.2-1.GA_redhat_1.ep7.el6 | 7.1.2-1.GA_redhat_1.ep7.el6 |
redhat/eap7-jboss-ec2-eap-samples | <7.1.2-1.GA_redhat_1.ep7.el6 | 7.1.2-1.GA_redhat_1.ep7.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.