Red Hat Security Advisory 2023-4629-01 - Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products and packaged under Red Hat JBoss Core Services, to allow for faster distribution of updates and for a more consistent update experience. This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.57 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.51 Service Pack 2, and includes bug fixes and enhancements, which are documented in the Release Notes linked to in the References section. Issues addressed include HTTP response splitting, bypass, integer overflow, and use-after-free vulnerabilities.
6c109e8112c245ff647417e707926d11d65d612b66e7ae46f1f05cb3ab724077
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 security update
Advisory ID: RHSA-2023:4629-01
Product: Red Hat JBoss Core Services
Advisory URL: https://access.redhat.com/errata/RHSA-2023:4629
Issue date: 2023-08-15
CVE Names: CVE-2022-24963 CVE-2022-36760 CVE-2022-37436
CVE-2022-48279 CVE-2023-24021 CVE-2023-27522
CVE-2023-28319 CVE-2023-28321 CVE-2023-28322
=====================================================================
1. Summary:
An update is now available for Red Hat JBoss Core Services.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat JBoss Core Services on RHEL 7 Server - noarch, x86_64
Red Hat JBoss Core Services on RHEL 8 - noarch, x86_64
3. Description:
Red Hat JBoss Core Services is a set of supplementary software for Red Hat
JBoss middleware products. This software, such as Apache HTTP Server, is
common to multiple JBoss middleware products and packaged under Red Hat
JBoss Core Services, to allow for faster distribution of updates and for a
more consistent update experience.
This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.57
serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server
2.4.51 Service Pack 2, and includes bug fixes and enhancements, which are
documented in the Release Notes linked to in the References section.
Security Fix(es):
* apr-util: integer overflow/wraparound in apr_encode (CVE-2022-24963)
* httpd: mod_proxy_ajp: Possible request smuggling (CVE-2022-36760)
* httpd: mod_proxy: HTTP response splitting (CVE-2022-37436)
* mod_security: incorrect parsing of HTTP multipart requests leads to web
application firewall bypass (CVE-2022-48279)
* modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to
web application firewall bypass (CVE-2023-24021)
* httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)
* curl: use after free in SSH sha256 fingerprint check (CVE-2023-28319)
* curl: IDN wildcard match may lead to Improper Cerificate Validation
(CVE-2023-28321)
* curl: more POST-after-PUT confusion (CVE-2023-28322)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
2161773 - CVE-2022-37436 httpd: mod_proxy: HTTP response splitting
2161777 - CVE-2022-36760 httpd: mod_proxy_ajp: Possible request smuggling
2163615 - CVE-2023-24021 modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to web application firewall bypass
2163622 - CVE-2022-48279 mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass
2169465 - CVE-2022-24963 apr: integer overflow/wraparound in apr_encode
2176211 - CVE-2023-27522 httpd: mod_proxy_uwsgi HTTP response splitting
2196778 - CVE-2023-28319 curl: use after free in SSH sha256 fingerprint check
2196786 - CVE-2023-28321 curl: IDN wildcard match may lead to Improper Cerificate Validation
2196793 - CVE-2023-28322 curl: more POST-after-PUT confusion
6. Package List:
Red Hat JBoss Core Services on RHEL 7 Server:
Source:
jbcs-httpd24-apr-1.7.0-8.el7jbcs.src.rpm
jbcs-httpd24-apr-util-1.6.1-102.el7jbcs.src.rpm
jbcs-httpd24-curl-8.2.1-1.el7jbcs.src.rpm
jbcs-httpd24-httpd-2.4.57-5.el7jbcs.src.rpm
jbcs-httpd24-mod_http2-1.15.19-28.el7jbcs.src.rpm
jbcs-httpd24-mod_jk-1.2.48-51.redhat_1.el7jbcs.src.rpm
jbcs-httpd24-mod_md-2.4.0-25.el7jbcs.src.rpm
jbcs-httpd24-mod_proxy_cluster-1.3.19-4.el7jbcs.src.rpm
jbcs-httpd24-mod_security-2.9.3-29.el7jbcs.src.rpm
noarch:
jbcs-httpd24-httpd-manual-2.4.57-5.el7jbcs.noarch.rpm
x86_64:
jbcs-httpd24-apr-1.7.0-8.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-debuginfo-1.7.0-8.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-devel-1.7.0-8.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-debuginfo-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-devel-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-ldap-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-mysql-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-nss-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-odbc-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-openssl-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-curl-8.2.1-1.el7jbcs.x86_64.rpm
jbcs-httpd24-curl-debuginfo-8.2.1-1.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-debuginfo-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-devel-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-selinux-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-tools-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-libcurl-8.2.1-1.el7jbcs.x86_64.rpm
jbcs-httpd24-libcurl-devel-8.2.1-1.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-1.15.19-28.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-debuginfo-1.15.19-28.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-1.2.48-51.redhat_1.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-debuginfo-1.2.48-51.redhat_1.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_ldap-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_md-2.4.0-25.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_md-debuginfo-2.4.0-25.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_cluster-1.3.19-4.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_cluster-debuginfo-1.3.19-4.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_html-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_security-2.9.3-29.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_security-debuginfo-2.9.3-29.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_session-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_ssl-2.4.57-5.el7jbcs.x86_64.rpm
Red Hat JBoss Core Services on RHEL 8:
Source:
jbcs-httpd24-apr-1.7.0-8.el8jbcs.src.rpm
jbcs-httpd24-apr-util-1.6.1-102.el8jbcs.src.rpm
jbcs-httpd24-curl-8.2.1-1.el8jbcs.src.rpm
jbcs-httpd24-httpd-2.4.57-5.el8jbcs.src.rpm
jbcs-httpd24-mod_http2-1.15.19-28.el8jbcs.src.rpm
jbcs-httpd24-mod_jk-1.2.48-51.redhat_1.el8jbcs.src.rpm
jbcs-httpd24-mod_md-2.4.0-25.el8jbcs.src.rpm
jbcs-httpd24-mod_proxy_cluster-1.3.19-4.el8jbcs.src.rpm
jbcs-httpd24-mod_security-2.9.3-29.el8jbcs.src.rpm
noarch:
jbcs-httpd24-httpd-manual-2.4.57-5.el8jbcs.noarch.rpm
x86_64:
jbcs-httpd24-apr-1.7.0-8.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-debuginfo-1.7.0-8.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-devel-1.7.0-8.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-devel-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-ldap-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-ldap-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-mysql-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-mysql-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-nss-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-nss-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-odbc-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-odbc-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-openssl-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-openssl-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-curl-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-curl-debuginfo-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-devel-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-selinux-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-tools-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-tools-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-debuginfo-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-devel-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-1.15.19-28.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-debuginfo-1.15.19-28.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-1.2.48-51.redhat_1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-debuginfo-1.2.48-51.redhat_1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ldap-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ldap-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_md-2.4.0-25.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_md-debuginfo-2.4.0-25.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_cluster-1.3.19-4.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_cluster-debuginfo-1.3.19-4.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_html-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_html-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_security-2.9.3-29.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_security-debuginfo-2.9.3-29.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_session-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_session-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ssl-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ssl-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2022-24963
https://access.redhat.com/security/cve/CVE-2022-36760
https://access.redhat.com/security/cve/CVE-2022-37436
https://access.redhat.com/security/cve/CVE-2022-48279
https://access.redhat.com/security/cve/CVE-2023-24021
https://access.redhat.com/security/cve/CVE-2023-27522
https://access.redhat.com/security/cve/CVE-2023-28319
https://access.redhat.com/security/cve/CVE-2023-28321
https://access.redhat.com/security/cve/CVE-2023-28322
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCAAGBQJk2938AAoJENzjgjWX9erEtTsP/3LmmBo74lDl/6hEmS7CVjrG
tNDPsAWewTMp9k1SOFqRtVY/B5lFTUMP47nAlozHcVwtqfr8hNTRNot0FgrZZJBM
lHqzvNGLZBFSDP4/otKRj37kTi9N2LTBj2CUWok72XbQlxO0Lyqa33XR4LbqMdzk
ZZ/Bx2n6bi8hzGSr2ESXGv+PFl0XsjMZH4XAeU/XOR6kThlOJPAKnl+jzA3r2ip6
EJrOwDM1Kh0oXs6+aVC7aKkqdihRmxbmONzVjv3EGt/CfEoJCf9XmFKfnEugEP8W
EGomu/5iwcYDYoauRR/WGf49MylrOEiqGYkglkbXH5G8iMGpZTuSqnqK0wzdPhgJ
xwDaid3+JPxB0tbtaBpEdH1trYNxrySvVD2XEe8UP5sdft8Ix9tOndHGOgl2P7I2
ws64DPAL32H4TyoiuXAid0tPIsSPzPuBBupW2sMI0LBmKSsiQ83Q3foYXDlLo+FM
V5qtHcsKpeXsyJ27brIMgT2mRm8NL26qGmqsp+u1Jq2xceNzn8H9O2HbVCUQXrXo
RofB2qkwwopjW5T0xun9WRle6uWuzzVQQXidT4zlmt5L6Q5myJ56/LD6mL1sIfRg
BnoZbUpjOxwP2SWNHPZvxCiu0hN7nQUQKzP+kTkeKVOIx60KY/xmK4ROmimVR8lB
K4ikAMvb9gMm7tCnaD5E
=zxHu
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce