First published: Tue Oct 17 2023(Updated: )
Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.<br>This release of Red Hat JBoss Web Server 5.7.5 serves as a replacement for Red Hat JBoss Web Server 5.7.4. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes, linked to in the References section.<br>Security Fix(es):<br><li> tomcat: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)</li> A Red Hat Security Bulletin which addresses further details about this flaw is available in the References section.<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Web Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:5784 is high.
Red Hat JBoss Enterprise Web Server is affected by RHSA-2023:5784.
You can find more information about RHSA-2023:5784 on the Red Hat Security Advisory page: https://access.redhat.com/errata/RHSA-2023:5784
To fix RHSA-2023:5784, apply the security update provided by Red Hat.
Yes, you can find the bug report for RHSA-2023:5784 on Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=2242803