Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Red Hat JBoss EAP 7.4.9 RHSA-2023-0756-01 Important Integer Overflow

red hat
Calendar Grey February 14, 2023
Scroller Redhat
Crucial update issued for Red Hat JBoss EAP tackling severe vulnerabilities related to integer overflow and potential exposure of sensitive data.
JBoss EAP XP 4.0.0.GA Security release on the EAP 7.4.9 base

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

This is a cumulative patch release zip for the JBoss EAP XP 4.0.0 runtime distribution for use with EAP 7.4.9.
Security Fix(es):
* libksba: integer overflow to code execution (CVE-2022-47629)
* okhttp: information disclosure via improperly used cryptographic function (CVE-2021-0341)

References

https://access.redhat.com/security/cve/CVE-2021-0341 https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification#important https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/red_hat_jboss_eap_xp_4.0.0_release_notes/index https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html/jboss_eap_xp_4.0_upgrade_and_migration_guide/index https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/using_jboss_eap_xp_4.0.0/index

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:0756-01
Product: Red Hat JBoss Enterprise Application Platform
Issue date: 2023-02-14

Topic

JBoss EAP XP 4.0.0.GA Security release on the EAP 7.4.9 base. Seereferences for release notes.Red Hat Product Security has rated this update as having a security impactofImportant. A Common Vulnerability Scoring System (CVSS) base score, whichgives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2154086 - CVE-2021-0341 okhttp: information disclosure via improperly used cryptographic function

2161571 - CVE-2022-47629 libksba: integer overflow to code execution

5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

JBEAP-24408 - EAP XP 4.0.0.GA for EAP 7.4.9

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.