RHSA-2018:1249: Important: jboss-ec2-eap package for EAP 7.1.2
The eap7-jboss-ec2-eap packages provide scripts for Red Hat JBoss Enterprise Application Platform running on the Amazon Web Services (AWS) Elastic Compute Cloud (EC2).<br>With this update, the eap7-jboss-ec2-eap package has been updated to ensure<br>compatibility with Red Hat JBoss Enterprise Application Platform 7.1.2.<br>Refer to the JBoss Enterprise Application Platform 7.1 Release Notes, linked to in the References section, for information on the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix</li> of CVE-2016-4993) (CVE-2018-1067)<br><li> wildfly-undertow: undertow: Path traversal in ServletResourceManager class</li> (CVE-2018-1047)<br><li> slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088)</li> Red Hat would like to thank Ammarit Thongthua and Nattakit Intarasorn (Deloitte Thailand Pentest team) for reporting CVE-2018-1067, and Chris McCown for reporting CVE-2018-8088.<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:1249?
The severity of RHSA-2018:1249 is classified as moderate.
How do I fix RHSA-2018:1249?
To fix RHSA-2018:1249, update the eap7-jboss-ec2-eap package to version 7.1.2-1.GA_redhat_1.ep7.el7 or later.
Which packages are affected by RHSA-2018:1249?
Affected packages include eap7-jboss-ec2-eap and eap7-jboss-ec2-eap-samples across different versions of Red Hat Enterprise Linux.
Is it mandatory to apply the update for RHSA-2018:1249?
It is highly recommended to apply the update for RHSA-2018:1249 to ensure compatibility and security.
Does RHSA-2018:1249 impact Red Hat JBoss Enterprise Application Platform on AWS EC2?
Yes, RHSA-2018:1249 specifically addresses compatibility issues for Red Hat JBoss Enterprise Application Platform running on AWS EC2.