RHSA-2021:5140: Low: Red Hat JBoss Enterprise Application Platform 7.4 security update
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.4.Security Fix(es): log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value (CVE-2021-44228) For more details about the security issue(s), including the impact, a CVSS score, and other related information, see the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:5140?
The severity of RHSA-2021:5140 is classified as critical due to the remote code execution vulnerability it addresses.
How do I fix RHSA-2021:5140?
To fix RHSA-2021:5140, update your Red Hat JBoss Enterprise Application Platform to the latest version provided in the advisory.
What systems are affected by RHSA-2021:5140?
RHSA-2021:5140 affects Red Hat JBoss Enterprise Application Platform version 7.4 that utilizes log4j-core.
What are the main vulnerabilities addressed in RHSA-2021:5140?
RHSA-2021:5140 addresses vulnerabilities in log4j-core that could lead to remote code execution.
Is there a workaround for RHSA-2021:5140?
Temporary workarounds include disabling vulnerable features or limiting network access until a patch is applied.