A flaw was found in Wildfly, where it returns an incorrect caller principal under certain heavily concurrent situations when Elytron Security is used. This flaw allows an attacker to gain improper access to information they should not have.
A flaw was found in undertow. The undertow client is not checking the server identity the server certificate presents in HTTPS connections. This is a compulsory step ( that should at least be performed by default) in HTTPS and in http/2.
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
A flaw was found in Undertow where a potential security issue in flow control handling by browser over HTTP/2 may potentially cause overhead or DOS in the server. The highest impact of this vulnerability is availability.(incomplete fix for CVE-2021-3629)
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
A flaw was found in undertow where HTTP2SourceChannel fails to write final frame under some circumstances may result in DoS. The highest impact of this vulnerability is availability.
Moderate: Red Hat JBoss Enterprise Application Platform 7.4.15 Security update
Low: Red Hat JBoss Enterprise Application Platform 7.4 security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.16 Security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.17 Security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.18 Security update
Important: Red Hat JBoss Enterprise Application Platform 7.4 security update
Critical: Red Hat JBoss Enterprise Application Platform 7.4 security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.19 Security update
Moderate: Red Hat JBoss Enterprise Application Platform 7.4.20 Security update
Important: Red Hat JBoss Enterprise Application Platform 7.4 security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.21 security update
Important: Red Hat JBoss Enterprise Application Platform 7.4 .21 security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.22 security update
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.8 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.7, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.8 Release Notes for information about the most significant bug fixes and enhancements included in this release.Security Fix(es): undertow: DoS can be achieved as Undertow server waits for the LASTCHUNK forever for EJB invocations (CVE-2022-2764) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
A flaw was found in Undertow with EJB invocations. This flaw allows an attacker to generate a valid HTTP request and send it to the server on an established connection after removing the LASTCHUNK from the bytes, causing a denial of service.
Important: Red Hat JBoss Enterprise Application Platform 7.4.13 security update
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.4.Security Fix(es): log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305) log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307) log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender (CVE-2021-4104) log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.This release of Red Hat JBoss Enterprise Application Platform 7.4.3 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.2 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.3 Release Notes for information about the most significant bug fixes and enhancements included in this release.Security Fix(es): undertow: client side invocation timeout raised when calling over HTTP2 (CVE-2021-3859) EAP 7: Incomplete fix of CVE-2016-4978 in HornetQ library (CVE-2021-20318) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
It was found that HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
Important: Red Hat JBoss Enterprise Application Platform 7.4.12 security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.14 security update
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jbossas init script and its content executed with root privileges when jbossas service is started, stopped or restarted.