RHSA-2024:2693: Moderate: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP4 security update
Moderate: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP4 security update
Other sources
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products and packaged under Red Hat JBoss Core Services, to allow for faster distribution of updates and for a more consistent update experience.This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.57 Service Pack 4 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.57 Service Pack 3, and includes bug fixes and enhancements, which are documented in the Release Notes linked to in the References section.Security Fix(es): curl: Usage of disabled protocol (CVE-2024-2004) curl: QUIC certificate check bypass with wolfSSL (CVE-2024-2379) curl: HTTP/2 push headers memory-leak (CVE-2024-2398) curl: TLS certificate check bypass with mbedTLS (CVE-2024-2466) jbcs-httpd24-httpd: httpd: CONTINUATION frames DoS (CVE-2024-27316) jbcs-httpd24-modhttp2: httpd: CONTINUATION frames DoS (CVE-2024-27316) jbcs-httpd24-nghttp2: httpd: CONTINUATION frames DoS (CVE-2024-27316) jbcs-httpd24-nghttp2: nghttp2: CONTINUATION frames DoS (CVE-2024-28182) A Red Hat Security Bulletin which addresses further details about this flaw is available in the References section.For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2693?
The severity of RHSA-2024:2693 is classified as moderate.
How do I fix RHSA-2024:2693?
To fix RHSA-2024:2693, update to the affected package versions specified in the advisory.
Which Red Hat JBoss Core Services packages are affected by RHSA-2024:2693?
The affected packages include jbcs-httpd24-curl, jbcs-httpd24-httpd, and jbcs-httpd24-nghttp2 among others.
When was RHSA-2024:2693 released?
RHSA-2024:2693 was released as a security update to address vulnerabilities in certain packages.
What are the implications of not addressing RHSA-2024:2693?
Not addressing RHSA-2024:2693 may expose systems to security vulnerabilities that could be exploited.