First published: Wed May 19 2021(Updated: )
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.<br>This release of Red Hat JBoss Enterprise Application Platform 7.3.7 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.3.6, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.3.7 Release Notes for information about the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> velocity: arbitrary code execution when attacker is able to modify templates (CVE-2020-13936)</li> <li> netty: Information disclosure via the local system temporary directory (CVE-2021-21290)</li> <li> netty: possible request smuggling in HTTP/2 due missing validation (CVE-2021-21295)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-artemis-wildfly-integration | <1.0.4-1.redhat_00001.1.el8ea | 1.0.4-1.redhat_00001.1.el8ea |
redhat/eap7-bouncycastle | <1.68.0-2.redhat_00005.1.el8ea | 1.68.0-2.redhat_00005.1.el8ea |
redhat/eap7-hal-console | <3.2.14-1.Final_redhat_00001.1.el8ea | 3.2.14-1.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-genericjms | <2.0.9-1.Final_redhat_00001.1.el8ea | 2.0.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-marshalling | <2.0.11-1.Final_redhat_00001.1.el8ea | 2.0.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-weld | <3.1-api-3.1.0-6.SP3_redhat_00001.1.el8ea | 3.1-api-3.1.0-6.SP3_redhat_00001.1.el8ea |
redhat/eap7-jgroups-kubernetes | <1.0.16-1.Final_redhat_00001.1.el8ea | 1.0.16-1.Final_redhat_00001.1.el8ea |
redhat/eap7-netty | <4.1.60-1.Final_redhat_00001.1.el8ea | 4.1.60-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-undertow | <2.0.35-1.SP1_redhat_00001.1.el8ea | 2.0.35-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-velocity | <2.3.0-1.redhat_00001.1.el8ea | 2.3.0-1.redhat_00001.1.el8ea |
redhat/eap7-weld-core | <3.1.6-1.Final_redhat_00001.1.el8ea | 3.1.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <7.3.7-1.GA_redhat_00002.1.el8ea | 7.3.7-1.GA_redhat_00002.1.el8ea |
redhat/eap7-wildfly-elytron | <1.10.12-1.Final_redhat_00001.1.el8ea | 1.10.12-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client | <1.0.26-1.Final_redhat_00001.1.el8ea | 1.0.26-1.Final_redhat_00001.1.el8ea |
redhat/eap7-xalan-j2 | <2.7.1-36.redhat_00013.1.el8ea | 2.7.1-36.redhat_00013.1.el8ea |
redhat/eap7-yasson | <1.0.9-1.redhat_00001.1.el8ea | 1.0.9-1.redhat_00001.1.el8ea |
redhat/eap7-bouncycastle-mail | <1.68.0-2.redhat_00005.1.el8ea | 1.68.0-2.redhat_00005.1.el8ea |
redhat/eap7-bouncycastle-pkix | <1.68.0-2.redhat_00005.1.el8ea | 1.68.0-2.redhat_00005.1.el8ea |
redhat/eap7-bouncycastle-prov | <1.68.0-2.redhat_00005.1.el8ea | 1.68.0-2.redhat_00005.1.el8ea |
redhat/eap7-infinispan-cachestore-jdbc | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan-cachestore-remote | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan-client-hotrod | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan-commons | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan-core | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan-hibernate-cache-commons | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan-hibernate-cache-spi | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan-hibernate-cache-v53 | <9.4.22-3.Final_redhat_00001.1.el8ea | 9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-common-api | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-common-impl | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-common-spi | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-core-api | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-core-impl | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-deployers-common | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-jdbc | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-validator | <1.4.30-1.Final_redhat_00001.1.el8ea | 1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-marshalling-river | <2.0.11-1.Final_redhat_00001.1.el8ea | 2.0.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration-cli | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-core | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-eap6.4 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-eap6.4-to-eap7.3 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.0 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.1 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.2 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.2-to-eap7.3 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.3-server | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly10.0 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly10.1 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly11.0 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly12.0 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly13.0-server | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly14.0-server | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly15.0-server | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly16.0-server | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly17.0-server | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly18.0-server | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly8.2 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly9.0 | <1.7.2-6.Final_redhat_00007.1.el8ea | 1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-weld | <3.1-api-weld-api-3.1.0-6.SP3_redhat_00001.1.el8ea | 3.1-api-weld-api-3.1.0-6.SP3_redhat_00001.1.el8ea |
redhat/eap7-jboss-weld | <3.1-api-weld-spi-3.1.0-6.SP3_redhat_00001.1.el8ea | 3.1-api-weld-spi-3.1.0-6.SP3_redhat_00001.1.el8ea |
redhat/eap7-netty-all | <4.1.60-1.Final_redhat_00001.1.el8ea | 4.1.60-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-atom-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-cdi | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-client | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-client-microprofile | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-crypto | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jackson-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jackson2-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jaxb-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jaxrs | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jettison-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jose-jwt | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jsapi | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-json-binding-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-json-p-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-multipart-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-rxjava2 | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-spring | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-validator-provider | <11-3.11.4-1.Final_redhat_00001.1.el8ea | 11-3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy-yaml-provider | <3.11.4-1.Final_redhat_00001.1.el8ea | 3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-velocity-engine-core | <2.3.0-1.redhat_00001.1.el8ea | 2.3.0-1.redhat_00001.1.el8ea |
redhat/eap7-weld-core-impl | <3.1.6-1.Final_redhat_00001.1.el8ea | 3.1.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-core-jsf | <3.1.6-1.Final_redhat_00001.1.el8ea | 3.1.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-ejb | <3.1.6-1.Final_redhat_00001.1.el8ea | 3.1.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-jta | <3.1.6-1.Final_redhat_00001.1.el8ea | 3.1.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-probe-core | <3.1.6-1.Final_redhat_00001.1.el8ea | 3.1.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-web | <3.1.6-1.Final_redhat_00001.1.el8ea | 3.1.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-elytron-tool | <1.10.12-1.Final_redhat_00001.1.el8ea | 1.10.12-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client-common | <1.0.26-1.Final_redhat_00001.1.el8ea | 1.0.26-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-ejb-client | <1.0.26-1.Final_redhat_00001.1.el8ea | 1.0.26-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-naming-client | <1.0.26-1.Final_redhat_00001.1.el8ea | 1.0.26-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-transaction-client | <1.0.26-1.Final_redhat_00001.1.el8ea | 1.0.26-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-javadocs | <7.3.7-1.GA_redhat_00002.1.el8ea | 7.3.7-1.GA_redhat_00002.1.el8ea |
redhat/eap7-wildfly-modules | <7.3.7-1.GA_redhat_00002.1.el8ea | 7.3.7-1.GA_redhat_00002.1.el8ea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.