First published: Mon Jul 08 2024(Updated: )
This asynchronous patch is a security update zip for the JBoss EAP XP 4.0.2 runtime distribution for use with EAP 7.4.17.<br>Security Fix(es):<br><li> jose4j: denial of service via specially crafted JWE (CVE-2023-51775) </li> A Red Hat Security Bulletin which addresses further details about the Rapid Reset flaw is available in the References section.<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Application Platform | ||
Red Hat JBoss EAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:4386 is classified as moderate.
To fix RHSA-2024:4386, users should apply the asynchronous patch provided in the security update for JBoss EAP XP 4.0.2.
RHSA-2024:4386 addresses a denial of service vulnerability via specially crafted JWE as indicated by CVE-2023-51775.
RHSA-2024:4386 affects Red Hat JBoss EAP and JBoss EAP XP runtimes.
RHSA-2024:4386 was released as a security update for JBoss EAP on the specified date in 2024.