RHSA-2022:1296LowCVSS 8.8
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.4 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2021-4104 — log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender CVE-2021-44832 — log4j-core: remote code execution via JDBC Appender CVE-2021-45046 — log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228) CVE-2021-45105 — log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern CVE-2022-23302 — log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink CVE-2022-23305 — log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender CVE-2022-23307 — log4j: Unsafe deserialization flaw in Chainsaw log viewer
🔗 References (38)
- selfhttps://access.redhat.com/errata/RHSA-2022:1296
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031667
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032580
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034067
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2035951
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041967
- externalhttps://issues.redhat.com/browse/JBEAP-22105
- externalhttps://issues.redhat.com/browse/JBEAP-22385
- externalhttps://issues.redhat.com/browse/JBEAP-22731
- externalhttps://issues.redhat.com/browse/JBEAP-22738
- externalhttps://issues.redhat.com/browse/JBEAP-22819
- externalhttps://issues.redhat.com/browse/JBEAP-22839
- externalhttps://issues.redhat.com/browse/JBEAP-22864
- externalhttps://issues.redhat.com/browse/JBEAP-22899
- externalhttps://issues.redhat.com/browse/JBEAP-22904
- externalhttps://issues.redhat.com/browse/JBEAP-22911
- externalhttps://issues.redhat.com/browse/JBEAP-22912
- externalhttps://issues.redhat.com/browse/JBEAP-22913
- externalhttps://issues.redhat.com/browse/JBEAP-22935
- externalhttps://issues.redhat.com/browse/JBEAP-22945
- externalhttps://issues.redhat.com/browse/JBEAP-22973
- externalhttps://issues.redhat.com/browse/JBEAP-23038
- externalhttps://issues.redhat.com/browse/JBEAP-23040
- externalhttps://issues.redhat.com/browse/JBEAP-23045
- externalhttps://issues.redhat.com/browse/JBEAP-23101
- externalhttps://issues.redhat.com/browse/JBEAP-23105
- externalhttps://issues.redhat.com/browse/JBEAP-23143
- externalhttps://issues.redhat.com/browse/JBEAP-23177
- externalhttps://issues.redhat.com/browse/JBEAP-23323
- externalhttps://issues.redhat.com/browse/JBEAP-23373
- externalhttps://issues.redhat.com/browse/JBEAP-23374
- externalhttps://issues.redhat.com/browse/JBEAP-23375
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1296.json