First published: Wed Apr 25 2018(Updated: )
Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server.<br>This release of Red Hat JBoss Enterprise Application Platform 7.1.2 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.1.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) (CVE-2018-1067)</li> <li> wildfly-undertow: undertow: Path traversal in ServletResourceManager class (CVE-2018-1047)</li> <li> slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088)</li> Red Hat would like to thank Ammarit Thongthua and Nattakit Intarasorn (Deloitte Thailand Pentest team) for reporting CVE-2018-1067, and Chris McCown for reporting CVE-2018-8088.<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
JBoss Enterprise Application Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2018:1251 is classified as important.
To fix RHSA-2018:1251, you should update to the latest version of Red Hat JBoss Enterprise Application Platform, specifically version 7.1.2.
RHSA-2018:1251 addresses multiple issues, including bugs that affect the performance and stability of Red Hat JBoss Enterprise Application Platform.
RHSA-2018:1251 is specifically applicable to Red Hat JBoss Enterprise Application Platform version 7.1.1 and earlier.
More information about RHSA-2018:1251 can be found in the Red Hat advisory and the associated bug reports.