RHEL 9 : Red Hat JBoss Enterprise Application Platform 8.0.2 Security update (Moderate) (RHSA-2024:3581)

high Nessus Plugin ID 200098

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2024:3581 advisory.

Red Hat JBoss Enterprise Application Platform 8 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 8.0.2 serves as a replacement for Red Hat JBoss Enterprise Application Platform 8.0.1, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 8.0.2 Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

* jberet-core: jberet: jberet-core logging database credentials [eap-8.0.z] (CVE-2024-1102)

* eap-galleon: custom provisioning creates unsecured http-invoker [eap-8.0.z] (CVE-2023-4503)

* eap: JBoss EAP: wildfly-elytron has a SSRF security issue [eap-8.0.z] (CVE-2024-1233)

* eap: JBoss EAP: OIDC app attempting to access the second tenant, the user should be prompted to log [eap-8.0.z] (CVE-2023-6236)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/security/updates/classification/#moderate

http://www.nessus.org/u?919aa761

http://www.nessus.org/u?f6e5f7c1

https://bugzilla.redhat.com/show_bug.cgi?id=2184751

https://bugzilla.redhat.com/show_bug.cgi?id=2250812

https://bugzilla.redhat.com/show_bug.cgi?id=2262060

https://bugzilla.redhat.com/show_bug.cgi?id=2262849

https://issues.redhat.com/browse/JBEAP-25251

https://issues.redhat.com/browse/JBEAP-25263

https://issues.redhat.com/browse/JBEAP-25292

https://issues.redhat.com/browse/JBEAP-25379

https://issues.redhat.com/browse/JBEAP-25638

https://issues.redhat.com/browse/JBEAP-25787

https://issues.redhat.com/browse/JBEAP-26024

https://issues.redhat.com/browse/JBEAP-26205

https://issues.redhat.com/browse/JBEAP-26224

https://issues.redhat.com/browse/JBEAP-26290

https://issues.redhat.com/browse/JBEAP-26407

https://issues.redhat.com/browse/JBEAP-26468

https://issues.redhat.com/browse/JBEAP-26529

https://issues.redhat.com/browse/JBEAP-26532

https://issues.redhat.com/browse/JBEAP-26573

https://issues.redhat.com/browse/JBEAP-26588

https://issues.redhat.com/browse/JBEAP-26635

https://issues.redhat.com/browse/JBEAP-26637

https://issues.redhat.com/browse/JBEAP-26642

https://issues.redhat.com/browse/JBEAP-26651

https://issues.redhat.com/browse/JBEAP-26677

https://issues.redhat.com/browse/JBEAP-26681

https://issues.redhat.com/browse/JBEAP-26758

https://issues.redhat.com/browse/JBEAP-26766

https://issues.redhat.com/browse/JBEAP-26770

https://issues.redhat.com/browse/JBEAP-26806

https://issues.redhat.com/browse/JBEAP-26812

https://issues.redhat.com/browse/JBEAP-26813

https://issues.redhat.com/browse/JBEAP-26832

https://issues.redhat.com/browse/JBEAP-26864

https://issues.redhat.com/browse/JBEAP-26868

https://issues.redhat.com/browse/JBEAP-26881

https://issues.redhat.com/browse/JBEAP-26933

https://issues.redhat.com/browse/JBEAP-26937

https://issues.redhat.com/browse/JBEAP-26954

https://issues.redhat.com/browse/JBEAP-27002

https://issues.redhat.com/browse/JBEAP-27009

https://access.redhat.com/errata/RHSA-2024:3581

Plugin Details

Severity: High

ID: 200098

File Name: redhat-RHSA-2024-3581.nasl

Version: 1.3

Type: local

Agent: unix

Published: 6/4/2024

Updated: 11/7/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2023-4503

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:eap8-fge-msg-simple, p-cpe:/a:redhat:enterprise_linux:eap8-apache-commons-codec, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-transaction-api, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-api, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-json-provider, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap8-lucene-queryparser, p-cpe:/a:redhat:enterprise_linux:eap8-jgroups-kubernetes, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-core, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-search, p-cpe:/a:redhat:enterprise_linux:eap8-velocity-engine-core, p-cpe:/a:redhat:enterprise_linux:eap8-fge-btf, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-client-hotrod-jakarta, p-cpe:/a:redhat:enterprise_linux:eap8-netty-buffer, cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap8-lucene-analyzers-common, p-cpe:/a:redhat:enterprise_linux:eap8-velocity, p-cpe:/a:redhat:enterprise_linux:eap8-httpcomponents-asyncclient, p-cpe:/a:redhat:enterprise_linux:eap8-jgroups, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-antlr4, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-crypto, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-http-naming-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap8-httpcomponents-client, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport, p-cpe:/a:redhat:enterprise_linux:eap8-rngom, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-providers, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-jberet, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-core-jakarta, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-base, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-unix-common, p-cpe:/a:redhat:enterprise_linux:eap8-atinject, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-modules, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-hibernate-cache-v62, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-api, p-cpe:/a:redhat:enterprise_linux:eap8-insights-java-client, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-classes-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-base, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-http-ejb-client, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-annotation-api, p-cpe:/a:redhat:enterprise_linux:eap8-netty-common, p-cpe:/a:redhat:enterprise_linux:eap8-txw2, p-cpe:/a:redhat:enterprise_linux:eap8-wss4j-ws-security-stax, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-servlet-api, p-cpe:/a:redhat:enterprise_linux:eap8-apache-commons-io, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-http-client-common, p-cpe:/a:redhat:enterprise_linux:eap8-angus, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-json-api, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-jackson2-provider, p-cpe:/a:redhat:enterprise_linux:eap8-angus-mail, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jts-integration, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk17, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jsr310, p-cpe:/a:redhat:enterprise_linux:eap8-snakeyaml, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-rxjava2, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-mail, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-ra, p-cpe:/a:redhat:enterprise_linux:eap8-antlr4-runtime, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-query, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-envers, p-cpe:/a:redhat:enterprise_linux:eap8-istack-commons-tools, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-rt, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-client-api, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-tools, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-databind, p-cpe:/a:redhat:enterprise_linux:eap8-elytron-web, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-jdbc, p-cpe:/a:redhat:enterprise_linux:eap8-lucene-solr, p-cpe:/a:redhat:enterprise_linux:eap8-guava, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-clustered-counter, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-ws-rs-api, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk11, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jdk8, p-cpe:/a:redhat:enterprise_linux:eap8-caffeine, p-cpe:/a:redhat:enterprise_linux:eap8-hal-console, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-impl, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver-dns, p-cpe:/a:redhat:enterprise_linux:eap8-wss4j-bindings, p-cpe:/a:redhat:enterprise_linux:eap8-wss4j, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-search-mapper-orm-orm6, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-runtime, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-xjc, p-cpe:/a:redhat:enterprise_linux:eap8-istack-commons-runtime, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-objectfilter, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-util, p-cpe:/a:redhat:enterprise_linux:eap8-codemodel, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-remote-query-client, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-interceptor-api, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-xml-bind-api, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-batch-api, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-hibernate-cache-commons, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-client, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-http-client, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-core, p-cpe:/a:redhat:enterprise_linux:eap8-sun-istack-commons, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-transaction-client, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-relaxng-datatype, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-search-backend-elasticsearch, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-core-spi, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-search-mapper-pojo-base, p-cpe:/a:redhat:enterprise_linux:eap8-wss4j-ws-security-common, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-json-p-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-module-jakarta-xmlbind-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-cdi, p-cpe:/a:redhat:enterprise_linux:eap8-apache-sshd, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-validator, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-cachestore-remote, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-deployers-common, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-hibernate-cache-spi, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-query-dsl, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-jms-api, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-java8, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-http-transaction-client, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-atom-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformat-cbor, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-validation-api, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler-proxy, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-json-binding-provider, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-search-util-common, p-cpe:/a:redhat:enterprise_linux:eap8-wsdl4j, p-cpe:/a:redhat:enterprise_linux:eap8-jberet-core, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-spi, p-cpe:/a:redhat:enterprise_linux:eap8-protostream, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-component-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-reactive-streams, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j-api, p-cpe:/a:redhat:enterprise_linux:eap8-java-classmate, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-validator-provider, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-dns, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jts-idlj, p-cpe:/a:redhat:enterprise_linux:eap8-wss4j-ws-security-dom, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jbossxts, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy, p-cpe:/a:redhat:enterprise_linux:eap8-angus-activation, p-cpe:/a:redhat:enterprise_linux:eap8-amazon-ion-java, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar, p-cpe:/a:redhat:enterprise_linux:eap8-httpcomponents-core, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-server, p-cpe:/a:redhat:enterprise_linux:eap8-lucene-join, p-cpe:/a:redhat:enterprise_linux:eap8-woodstox-core, p-cpe:/a:redhat:enterprise_linux:eap8-yasson, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jbosstxbridge, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-validator, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-jsapi, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-search-backend-lucene, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-core, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-core, p-cpe:/a:redhat:enterprise_linux:eap8-joda-time, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-json, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-client, p-cpe:/a:redhat:enterprise_linux:eap8-narayana, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-bridge, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap8-lucene-queries, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-multipart-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jasypt, p-cpe:/a:redhat:enterprise_linux:eap8-log4j2-jboss-logmanager, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-ejb-client, p-cpe:/a:redhat:enterprise_linux:eap8-stax2-api, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-cdi-embedded-jakarta, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-cachestore-jdbc-common-jakarta, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j, p-cpe:/a:redhat:enterprise_linux:eap8-xsom, p-cpe:/a:redhat:enterprise_linux:eap8-ws-commons-xmlschema, p-cpe:/a:redhat:enterprise_linux:eap8-guava-failureaccess, p-cpe:/a:redhat:enterprise_linux:eap8-guava-libraries, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-activation, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-commons-jakarta, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-jxc, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-clustered-lock, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-cert-helper, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-search-engine, p-cpe:/a:redhat:enterprise_linux:eap8-apache-commons-beanutils, p-cpe:/a:redhat:enterprise_linux:eap8-javaee-jpa-spec, p-cpe:/a:redhat:enterprise_linux:eap8-wss4j-ws-security-policy-stax, p-cpe:/a:redhat:enterprise_linux:eap8-netty, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-cdi-common-jakarta, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-validator-cdi, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-query-core, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-cachestore-jdbc-jakarta, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-integration, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-services, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-http, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-jaxb-provider, p-cpe:/a:redhat:enterprise_linux:eap8-gson, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron-tool, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformats-binary, p-cpe:/a:redhat:enterprise_linux:eap8-jose4j, p-cpe:/a:redhat:enterprise_linux:eap8-wss4j-policy, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-lucene-core, p-cpe:/a:redhat:enterprise_linux:eap8-lucene-facet, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-socks, p-cpe:/a:redhat:enterprise_linux:eap8-infinispan-cdi-remote-jakarta

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 6/4/2024

Vulnerability Publication Date: 12/4/2023

Reference Information

CVE: CVE-2023-4503, CVE-2023-6236, CVE-2024-1102, CVE-2024-1233

CWE: 345, 523, 665, 918

IAVA: 2024-A-0331

RHSA: 2024:3581