First published: Thu Jan 20 2022(Updated: )
This release of Red Hat build of Eclipse Vert.x 4.1.8 GA includes security updates. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> log4j-core: remote code execution via JDBC Appender (CVE-2021-44832)</li> <li> log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228) (CVE-2021-45046)</li> <li> log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern (CVE-2021-45105)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2022:0083 addresses critical vulnerabilities associated with remote code execution in log4j-core.
To remediate RHSA-2022:0083, update to the fixed version of Eclipse Vert.x as per the provided security advisory.
RHSA-2022:0083 includes fixes for CVE-2021-44832 and other critical vulnerabilities in log4j-core.
RHSA-2022:0083 is applicable to systems running Red Hat build of Eclipse Vert.x affected by the specific vulnerabilities.
After applying the patch for RHSA-2022:0083, verify the functionality of your applications and monitor for any unusual behavior.