-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Red Hat JBoss Enterprise Application Platform 7.4 security update
Advisory ID:       RHSA-2023:1184-01
Product:           Red Hat JBoss Enterprise Application Platform
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:1184
Issue date:        2023-03-09
CVE Names:         CVE-2023-1108 
====================================================================
1. Summary:

A security update is now available for Red Hat JBoss Enterprise Application
Platform 7.4.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java
applications based on the WildFly application runtime.

This asynchronous patch is a security update for Red Hat JBoss Enterprise
Application Platform 7.4.

Security Fix(es):

* undertow: Infinite loop in SslConduit during close (CVE-2023-1108)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgements, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2174246 - CVE-2023-1108 Undertow: Infinite loop in SslConduit during close

5. References:

https://access.redhat.com/security/cve/CVE-2023-1108
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=appplatform&version=7.4
https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/
https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZApNXdzjgjWX9erEAQi8HQ/+P7OCx4t2Z/SGbmy4wyGApBmvmWAu1KKA
xZTNTyTKRBxTplHQrFcctwMeZR7Sq9l8S1H+L1xN8v10zdh5bnNGYYrZyugtNzCj
t3GhR83p0RlS79syW1HYHT7rsD73tYi8xKn+47/QqyX1TVHVDS467sK/LhUfouUh
TzCpzvB0JglINKdRo64AH342mD/FXsSfmusYLsSXE6c4W6+zvvKE9uqyJTtyeYIp
UufVyLPBVUybdY3eohc/v/kHWJz3Lh5OJRSf5VWGtutyTJiqXoHj5DhxaGdczLE7
+uBIFZ26jCK18Svg4IqgRLZku5TmFAeo6JMQPqXd8jW2XNWJwTLNPrrBWGkfOVug
VsUdz6yQXrOWyBkWmH48u+RNtOwAiyR/TMfdD8MX+Oj6KWxWZgMG27XEYcJLNfuF
6CDOpox6pCOOoPKDcPv7Kc2yHqVftVAYtJ5rKr7pk6yG+P26Lg3vWe0XT5buu2cE
sRbQkdaVC5b32zymHTOU0Z2d2vi/DOu/lFzB/pLx58vo29sxnBSfY9CjGhn+MChd
RNo1diAPnkZbC8tJAQiVtUIbqA93hV+j2tnG4tDAz7jgXdUfTwW8X1UrAZNzonUR
Abvz5fFesWP4XxzRSVrxIk0o/XEnY7VtCLKvBurHALsuGZHu6/a+rDH4pwDha/WP
ZgS7lJPBosQ=6uKb
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-1184:01 Important: Red Hat JBoss Enterprise Application

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4

Summary

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.
This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.4.
Security Fix(es):
* undertow: Infinite loop in SslConduit during close (CVE-2023-1108)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2023-1108 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=appplatform&version=7.4 https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/ https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/

Package List


Severity
Advisory ID: RHSA-2023:1184-01
Product: Red Hat JBoss Enterprise Application Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2023:1184
Issued Date: : 2023-03-09
CVE Names: CVE-2023-1108

Topic

A security update is now available for Red Hat JBoss Enterprise ApplicationPlatform 7.4.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2174246 - CVE-2023-1108 Undertow: Infinite loop in SslConduit during close


Related News