Vulnerability Database
Blog
FAQ
Docs
RHSA-2024:5479
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2024:5479
Import Source
https://security.access.redhat.com/data/osv/RHSA-2024:5479.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2024:5479
Related
CVE-2024-28752
CVE-2024-29025
CVE-2024-29857
CVE-2024-30171
CVE-2024-30172
Published
2024-09-30T16:46:52Z
Modified
2024-11-15T21:15:12Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.3 Security update
Details
References
https://access.redhat.com/errata/RHSA-2024:5479
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/8.0/
https://bugzilla.redhat.com/show_bug.cgi?id=2270732
https://bugzilla.redhat.com/show_bug.cgi?id=2272907
https://bugzilla.redhat.com/show_bug.cgi?id=2276360
https://bugzilla.redhat.com/show_bug.cgi?id=2293025
https://bugzilla.redhat.com/show_bug.cgi?id=2293028
https://issues.redhat.com/browse/JBEAP-25224
https://issues.redhat.com/browse/JBEAP-26018
https://issues.redhat.com/browse/JBEAP-26696
https://issues.redhat.com/browse/JBEAP-26790
https://issues.redhat.com/browse/JBEAP-26791
https://issues.redhat.com/browse/JBEAP-26792
https://issues.redhat.com/browse/JBEAP-26802
https://issues.redhat.com/browse/JBEAP-26816
https://issues.redhat.com/browse/JBEAP-26823
https://issues.redhat.com/browse/JBEAP-26843
https://issues.redhat.com/browse/JBEAP-26886
https://issues.redhat.com/browse/JBEAP-26932
https://issues.redhat.com/browse/JBEAP-26948
https://issues.redhat.com/browse/JBEAP-26961
https://issues.redhat.com/browse/JBEAP-26962
https://issues.redhat.com/browse/JBEAP-26966
https://issues.redhat.com/browse/JBEAP-26986
https://issues.redhat.com/browse/JBEAP-27002
https://issues.redhat.com/browse/JBEAP-27019
https://issues.redhat.com/browse/JBEAP-27055
https://issues.redhat.com/browse/JBEAP-27090
https://issues.redhat.com/browse/JBEAP-27192
https://issues.redhat.com/browse/JBEAP-27194
https://issues.redhat.com/browse/JBEAP-27261
https://issues.redhat.com/browse/JBEAP-27262
https://issues.redhat.com/browse/JBEAP-27327
https://issues.redhat.com/browse/JBEAP-27356
https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5479.json
https://access.redhat.com/security/cve/CVE-2024-28752
https://www.cve.org/CVERecord?id=CVE-2024-28752
https://nvd.nist.gov/vuln/detail/CVE-2024-28752
https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt
https://github.com/advisories/GHSA-qmgx-j96g-4428
https://access.redhat.com/security/cve/CVE-2024-29025
https://www.cve.org/CVERecord?id=CVE-2024-29025
https://nvd.nist.gov/vuln/detail/CVE-2024-29025
https://gist.github.com/vietj/f558b8ea81ec6505f1e9a6ca283c9ae3
https://github.com/netty/netty/commit/0d0c6ed782d13d423586ad0c71737b2c7d02058c
https://github.com/netty/netty/security/advisories/GHSA-5jpm-x58v-624v
https://security.snyk.io/vuln/SNYK-JAVA-IONETTY-6483812
https://access.redhat.com/security/cve/CVE-2024-29857
https://www.cve.org/CVERecord?id=CVE-2024-29857
https://nvd.nist.gov/vuln/detail/CVE-2024-29857
https://access.redhat.com/security/cve/CVE-2024-30171
https://www.cve.org/CVERecord?id=CVE-2024-30171
https://nvd.nist.gov/vuln/detail/CVE-2024-30171
https://people.redhat.com/~hkario/marvin/
https://access.redhat.com/security/cve/CVE-2024-30172
https://www.cve.org/CVERecord?id=CVE-2024-30172
https://nvd.nist.gov/vuln/detail/CVE-2024-30172
https://www.bouncycastle.org/latest_releases.html
Affected packages
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-apache-cxf
Package
Name
eap8-apache-cxf
Purl
pkg:rpm/redhat/eap8-apache-cxf
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.4-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-apache-cxf-rt
Package
Name
eap8-apache-cxf-rt
Purl
pkg:rpm/redhat/eap8-apache-cxf-rt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.4-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-apache-cxf-services
Package
Name
eap8-apache-cxf-services
Purl
pkg:rpm/redhat/eap8-apache-cxf-services
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.4-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-apache-cxf-tools
Package
Name
eap8-apache-cxf-tools
Purl
pkg:rpm/redhat/eap8-apache-cxf-tools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.4-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-apache-cxf-xjc-utils
Package
Name
eap8-apache-cxf-xjc-utils
Purl
pkg:rpm/redhat/eap8-apache-cxf-xjc-utils
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.0-5.redhat_00003.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-cxf-xjc-boolean
Package
Name
eap8-cxf-xjc-boolean
Purl
pkg:rpm/redhat/eap8-cxf-xjc-boolean
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.0-5.redhat_00003.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-cxf-xjc-bug986
Package
Name
eap8-cxf-xjc-bug986
Purl
pkg:rpm/redhat/eap8-cxf-xjc-bug986
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.0-5.redhat_00003.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-cxf-xjc-dv
Package
Name
eap8-cxf-xjc-dv
Purl
pkg:rpm/redhat/eap8-cxf-xjc-dv
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.0-5.redhat_00003.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-cxf-xjc-runtime
Package
Name
eap8-cxf-xjc-runtime
Purl
pkg:rpm/redhat/eap8-cxf-xjc-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.0-5.redhat_00003.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-cxf-xjc-ts
Package
Name
eap8-cxf-xjc-ts
Purl
pkg:rpm/redhat/eap8-cxf-xjc-ts
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.0-5.redhat_00003.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-apache-commons-beanutils
Package
Name
eap8-apache-commons-beanutils
Purl
pkg:rpm/redhat/eap8-apache-commons-beanutils
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.9.4-13.redhat_00004.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-codemodel
Package
Name
eap8-codemodel
Purl
pkg:rpm/redhat/eap8-codemodel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-guava
Package
Name
eap8-guava
Purl
pkg:rpm/redhat/eap8-guava
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:33.0.0-1.jre_redhat_00002.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-guava-libraries
Package
Name
eap8-guava-libraries
Purl
pkg:rpm/redhat/eap8-guava-libraries
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:33.0.0-1.jre_redhat_00002.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-jakarta-servlet-api
Package
Name
eap8-jakarta-servlet-api
Purl
pkg:rpm/redhat/eap8-jakarta-servlet-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.0.0-5.redhat_00006.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-jaxb
Package
Name
eap8-jaxb
Purl
pkg:rpm/redhat/eap8-jaxb
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-jaxb-core
Package
Name
eap8-jaxb-core
Purl
pkg:rpm/redhat/eap8-jaxb-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-jaxb-jxc
Package
Name
eap8-jaxb-jxc
Purl
pkg:rpm/redhat/eap8-jaxb-jxc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-jaxb-runtime
Package
Name
eap8-jaxb-runtime
Purl
pkg:rpm/redhat/eap8-jaxb-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-jaxb-xjc
Package
Name
eap8-jaxb-xjc
Purl
pkg:rpm/redhat/eap8-jaxb-xjc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-jboss-openjdk-orb
Package
Name
eap8-jboss-openjdk-orb
Purl
pkg:rpm/redhat/eap8-jboss-openjdk-orb
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:10.1.0-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty
Package
Name
eap8-netty
Purl
pkg:rpm/redhat/eap8-netty
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-buffer
Package
Name
eap8-netty-buffer
Purl
pkg:rpm/redhat/eap8-netty-buffer
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-codec
Package
Name
eap8-netty-codec
Purl
pkg:rpm/redhat/eap8-netty-codec
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-codec-dns
Package
Name
eap8-netty-codec-dns
Purl
pkg:rpm/redhat/eap8-netty-codec-dns
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-codec-http
Package
Name
eap8-netty-codec-http
Purl
pkg:rpm/redhat/eap8-netty-codec-http
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-codec-socks
Package
Name
eap8-netty-codec-socks
Purl
pkg:rpm/redhat/eap8-netty-codec-socks
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-common
Package
Name
eap8-netty-common
Purl
pkg:rpm/redhat/eap8-netty-common
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-handler
Package
Name
eap8-netty-handler
Purl
pkg:rpm/redhat/eap8-netty-handler
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-handler-proxy
Package
Name
eap8-netty-handler-proxy
Purl
pkg:rpm/redhat/eap8-netty-handler-proxy
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-resolver
Package
Name
eap8-netty-resolver
Purl
pkg:rpm/redhat/eap8-netty-resolver
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-resolver-dns
Package
Name
eap8-netty-resolver-dns
Purl
pkg:rpm/redhat/eap8-netty-resolver-dns
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-transport
Package
Name
eap8-netty-transport
Purl
pkg:rpm/redhat/eap8-netty-transport
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-transport-classes-epoll
Package
Name
eap8-netty-transport-classes-epoll
Purl
pkg:rpm/redhat/eap8-netty-transport-classes-epoll
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-netty-transport-native-unix-common
Package
Name
eap8-netty-transport-native-unix-common
Purl
pkg:rpm/redhat/eap8-netty-transport-native-unix-common
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.108-1.Final_redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-relaxng-datatype
Package
Name
eap8-relaxng-datatype
Purl
pkg:rpm/redhat/eap8-relaxng-datatype
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-rngom
Package
Name
eap8-rngom
Purl
pkg:rpm/redhat/eap8-rngom
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-txw2
Package
Name
eap8-txw2
Purl
pkg:rpm/redhat/eap8-txw2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-wsdl4j
Package
Name
eap8-wsdl4j
Purl
pkg:rpm/redhat/eap8-wsdl4j
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-5.redhat_00008.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-xsom
Package
Name
eap8-xsom
Purl
pkg:rpm/redhat/eap8-xsom
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-2.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-bouncycastle
Package
Name
eap8-bouncycastle
Purl
pkg:rpm/redhat/eap8-bouncycastle
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.78.1-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-bouncycastle-jmail
Package
Name
eap8-bouncycastle-jmail
Purl
pkg:rpm/redhat/eap8-bouncycastle-jmail
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.78.1-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-bouncycastle-pg
Package
Name
eap8-bouncycastle-pg
Purl
pkg:rpm/redhat/eap8-bouncycastle-pg
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.78.1-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-bouncycastle-pkix
Package
Name
eap8-bouncycastle-pkix
Purl
pkg:rpm/redhat/eap8-bouncycastle-pkix
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.78.1-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-bouncycastle-prov
Package
Name
eap8-bouncycastle-prov
Purl
pkg:rpm/redhat/eap8-bouncycastle-prov
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.78.1-1.redhat_00001.1.el8eap
Red Hat:jboss_enterprise_application_platform:8.0::el8
/
eap8-bouncycastle-util
Package
Name
eap8-bouncycastle-util
Purl
pkg:rpm/redhat/eap8-bouncycastle-util
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.78.1-1.redhat_00001.1.el8eap
RHSA-2024:5479 - OSV