First published: Wed Jun 02 2021(Updated: )
These are CVE issues filed against XP1 releases that have been fixed in the underlying EAP 7.3.x base, so no changes to the EAP XP1 code base.<br>Security Fix(es):<br><li> velocity: arbitrary code execution when attacker is able to modify templates (CVE-2020-13936)</li> <li> bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible (CVE-2020-28052)</li> <li> jboss-remoting: Threads hold up forever in the EJB server by suppressing the ack from an EJB client (CVE-2020-35510)</li> <li> undertow: Possible regression in fix for CVE-2020-10687 (CVE-2021-20220)</li> <li> wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client (CVE-2021-20250)</li> <li> netty: Information disclosure via the local system temporary directory (CVE-2021-21290)</li> <li> guava: local information disclosure via temporary directory created with unsafe permissions (CVE-2020-8908)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.