Lucene search

K
redhatRedHatRHSA-2022:0216
HistoryJan 20, 2022 - 3:56 p.m.

(RHSA-2022:0216) Low: Red Hat JBoss Enterprise Application Platform 7.4 security update

2022-01-2015:56:27
access.redhat.com
99

0.976 High

EPSS

Percentile

100.0%

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.

This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.4.

Security Fix(es):

  • log4j-core: remote code execution via JDBC Appender (CVE-2021-44832)

  • log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228) (CVE-2021-45046)

  • log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern (CVE-2021-45105)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.