RHSA-2023:0556HighCVSS 9.8

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.9 Security update

Published
January 31, 2023
Last Modified
September 8, 2026

🔗 CVE IDs covered (20)

📋 Description

CVE-2015-9251 — jquery: Cross-site scripting via cross-domain ajax requests CVE-2016-10735 — bootstrap: XSS in the data-target attribute CVE-2017-18214 — nodejs-moment: Regular expression denial of service CVE-2018-14040 — bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute CVE-2018-14041 — bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy CVE-2018-14042 — bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip CVE-2019-8331 — bootstrap: XSS in the tooltip or popover data-template attribute CVE-2019-11358 — jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection CVE-2020-11022 — jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods CVE-2022-3143 — wildfly-elytron: possible timing attacks via use of unsafe comparator CVE-2022-40149 — jettison: parser crash by stackoverflow CVE-2022-40150 — jettison: memory exhaustion via user-supplied XML or JSON data CVE-2022-40152 — woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2022-45047 — mina-sshd: Java unsafe deserialization vulnerability CVE-2022-45693 — jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos CVE-2022-46363 — CXF: directory listing / code exfiltration CVE-2022-46364 — CXF: SSRF Vulnerability

🎯 Affected products200

  • Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.code-frame-7.0.0 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.core-7.4.5 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.generator-7.4.4 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.helper-function-name-7.1.0 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.helper-get-function-arity-7.0.0 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.helper-split-export-declaration-7.4.4 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.helpers-7.4.4 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.highlight-7.0.0 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.parser-7.4.5 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.template-7.4.4 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.traverse-7.4.5 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @babel.types-7.4.4 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @gar.promisify-1.1.3 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @mrmlnc.readdir-enhanced-2.2.1 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @nodelib.fs.stat-1.1.3 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @npmcli.fs-2.1.2 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @npmcli.move-file-2.0.1 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @tootallnate.once-2.0.0 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.c3-0.6.0 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-4.13.0 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-array-1.2.1 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-axis-1.0.10 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-brush-1.0.8 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-chord-1.0.7 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-collection-1.0.7 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-color-1.2.1 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-dispatch-1.0.6 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-drag-1.2.1 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • @types.d3-dsv-1.0.33 as a component of Red Hat JBoss Enterprise Application Platform 7.4.9
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: From the maintainer: For Apache MINA SSHD <= 2.9.1, do not use org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider to generate and later load your server's host key. Use separately generated host key files, for instance in OpenSSH format, and load them via a org.apache.sshd.common.keyprovider.FileKeyPairProvider instead. Or use a custom implementation instead of SimpleGeneratorHostKeyProvider that uses the OpenSSH format for storing and loading the host key (via classes OpenSSHKeyPairResourceWriter and OpenSSHKeyPairResourceParser).

🔗 References (44)