First published: Mon Jan 25 2021(Updated: )
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.<br>This release of Red Hat JBoss Enterprise Application Platform 7.3.5 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.3.4, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise<br>Application Platform 7.3.5 Release Notes for information about the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> wildfly: Potential Memory leak in Wildfly when using OpenTracing (CVE-2020-27822)</li> <li> undertow: special character in query results in server errors (CVE-2020-27782)</li> <li> wildfly-core: memory leak in WildFly host-controller in domain mode while not able to reconnect to domain-controller (CVE-2020-25689)</li> <li> httpclient: apache-httpclient: incorrect handling of malformed authority component in request URIs (CVE-2020-13956)</li> <li> wildfly: resource adapter logs plaintext JMS password at warning level on connection error (CVE-2020-25640)</li> <li> resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling (CVE-2020-25633)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, see the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-activemq-artemis | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-glassfish-jsf | <2.3.9-12.SP13_redhat_00001.1.el8ea | 2.3.9-12.SP13_redhat_00001.1.el8ea |
redhat/eap7-hal-console | <3.2.12-1.Final_redhat_00001.1.el8ea | 3.2.12-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate | <5.3.20-1.Final_redhat_00001.1.el8ea | 5.3.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-httpcomponents-client | <4.5.13-1.redhat_00001.1.el8ea | 4.5.13-1.redhat_00001.1.el8ea |
redhat/eap7-jboss-ejb-client | <4.0.37-1.Final_redhat_00001.1.el8ea | 4.0.37-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-genericjms | <2.0.8-1.Final_redhat_00001.1.el8ea | 2.0.8-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-modules | <1.11.0-1.Final_redhat_00001.1.el8ea | 1.11.0-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-remoting | <5.0.20-1.Final_redhat_00001.1.el8ea | 5.0.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-xnio-base | <3.7.12-1.Final_redhat_00001.1.el8ea | 3.7.12-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-opentracing-interceptors | <0.0.4.1-2.redhat_00002.1.el8ea | 0.0.4.1-2.redhat_00002.1.el8ea |
redhat/eap7-resteasy | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-undertow | <2.0.33-1.SP2_redhat_00001.1.el8ea | 2.0.33-1.SP2_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <7.3.5-2.GA_redhat_00001.1.el8ea | 7.3.5-2.GA_redhat_00001.1.el8ea |
redhat/eap7-wildfly-discovery | <1.2.1-1.Final_redhat_00001.1.el8ea | 1.2.1-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-elytron | <1.10.10-1.Final_redhat_00001.1.el8ea | 1.10.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client | <1.0.24-1.Final_redhat_00001.1.el8ea | 1.0.24-1.Final_redhat_00001.1.el8ea |
redhat/eap7-activemq-artemis-cli | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-commons | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-core-client | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-dto | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-hornetq-protocol | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-hqclient-protocol | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-jdbc-store | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-jms-client | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-jms-server | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-journal | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-ra | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-selector | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-server | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-service-extensions | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-activemq-artemis-tools | <2.9.0-7.redhat_00017.1.el8ea | 2.9.0-7.redhat_00017.1.el8ea |
redhat/eap7-hibernate-core | <5.3.20-1.Final_redhat_00001.1.el8ea | 5.3.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-entitymanager | <5.3.20-1.Final_redhat_00001.1.el8ea | 5.3.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-envers | <5.3.20-1.Final_redhat_00001.1.el8ea | 5.3.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-java8 | <5.3.20-1.Final_redhat_00001.1.el8ea | 5.3.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration-cli | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-core | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-eap6.4 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-eap6.4-to-eap7.3 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.0 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.1 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.2 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.2-to-eap7.3 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.3-server | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly10.0 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly10.1 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly11.0 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly12.0 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly13.0-server | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly14.0-server | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly15.0-server | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly16.0-server | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly17.0-server | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly18.0-server | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly8.2 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly9.0 | <1.7.2-4.Final_redhat_00005.1.el8ea | 1.7.2-4.Final_redhat_00005.1.el8ea |
redhat/eap7-narayana-compensations | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-jbosstxbridge | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-jbossxts | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-jts-idlj | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-jts-integration | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-restat-api | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-restat-bridge | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-restat-integration | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-restat-util | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-narayana-txframework | <5.9.10-1.Final_redhat_00001.1.el8ea | 5.9.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-atom-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-cdi | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-client | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-client-microprofile | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-crypto | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jackson-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jackson2-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jaxb-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jaxrs | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jettison-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jose-jwt | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jsapi | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-json-binding-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-json-p-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-multipart-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-rxjava2 | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-spring | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-validator-provider | <11-3.11.3-1.Final_redhat_00001.1.el8ea | 11-3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-yaml-provider | <3.11.3-1.Final_redhat_00001.1.el8ea | 3.11.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-discovery-client | <1.2.1-1.Final_redhat_00001.1.el8ea | 1.2.1-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-elytron-tool | <1.10.10-1.Final_redhat_00001.1.el8ea | 1.10.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client-common | <1.0.24-1.Final_redhat_00001.1.el8ea | 1.0.24-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-ejb-client | <1.0.24-1.Final_redhat_00001.1.el8ea | 1.0.24-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-naming-client | <1.0.24-1.Final_redhat_00001.1.el8ea | 1.0.24-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-transaction-client | <1.0.24-1.Final_redhat_00001.1.el8ea | 1.0.24-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-javadocs | <7.3.5-2.GA_redhat_00001.1.el8ea | 7.3.5-2.GA_redhat_00001.1.el8ea |
redhat/eap7-wildfly-modules | <7.3.5-2.GA_redhat_00001.1.el8ea | 7.3.5-2.GA_redhat_00001.1.el8ea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.