RHSA-2022:0146: Moderate: EAP XP 2 security update to CVE fixes in the EAP 7.3.x base
These are CVE issues filed against XP2 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP2 code base.Security Fix(es): undertow: potential security issue in flow control over HTTP/2 may lead to DOS (CVE-2021-3629) wildfly-elytron: possible timing attack in ScramServer (CVE-2021-3642) wildfly: incorrect JBOSSLOCALUSER challenge location may lead to giving access to all the local users (CVE-2021-3717) jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck (CVE-2021-37714) xml-security: XPath Transform abuse allows for information disclosure (CVE-2021-40690) resteasy: Error message exposes endpoint class information (CVE-2021-20289) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0146?
The severity of RHSA-2022:0146 is classified as moderate due to potential denial of service issues.
How do I fix RHSA-2022:0146?
To fix RHSA-2022:0146, update to the latest version of EAP 7.3.x that addresses the reported vulnerabilities.
What vulnerabilities are addressed in RHSA-2022:0146?
RHSA-2022:0146 addresses potential denial of service issues in HTTP/2 flow control (CVE-2021-3629).
Is there any code change in RHSA-2022:0146?
No, RHSA-2022:0146 does not involve changes to the EAP XP2 code base.
Who is affected by RHSA-2022:0146?
Users of EAP 7.3.x who implement the XP2 release are affected by RHSA-2022:0146.