First published: Wed Feb 02 2022(Updated: )
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.<br>This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.3.<br>Security Fix(es):<br><li> undertow: client side invocation timeout raised when calling over HTTP2 (CVE-2021-3859)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-undertow | <2.0.41-2.SP2_redhat_00001.1.el8ea | 2.0.41-2.SP2_redhat_00001.1.el8ea |
redhat/eap7-undertow | <2.0.41-2.SP2_redhat_00001.1.el7ea | 2.0.41-2.SP2_redhat_00001.1.el7ea |
redhat/eap7-undertow | <2.0.41-2.SP2_redhat_00001.1.el6ea | 2.0.41-2.SP2_redhat_00001.1.el6ea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:0405 is classified as critical due to the potential for client-side vulnerabilities in JBoss.
To fix RHSA-2022:0405, you need to update the eap7-undertow package to the version specified in the advisory for your system.
Versions of eap7-undertow up to 2.0.41-2.SP2_redhat_00001.1 for el6, el7, and el8 are affected by RHSA-2022:0405.
No official workaround has been provided for RHSA-2022:0405; updating to the patched version is recommended.
RHSA-2022:0405 was released as an asynchronous patch to address security vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.3.