JBoss Enterprise Application Platform 7.1 Update 3 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 7 have been discontinued and replaced with updates delivered on a repeating schedule, targeting a new release every 6 weeks.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

For more information see the following Red Hat Knowledgebase articles: Maintenance Release Changes in EAP 6.2+ and Updated Patch Management with EAP 6.2+

This update includes all fixes and changes from JBoss Enterprise Application Platform 7.1 Update 02

This update includes fixes for the following security related issues:

IDComponentSummary
CVE-2017-7525Documentationjackson-databind: incomplete fix for CVE-2017-7525 permits unsafe serialization via c3p0 libraries
CVE-2016-8657RPMjboss: jbossas writable config files allow privilege escalation
CVE-2018-7489Serverjackson-databind Remote Code Execution (RCE)
CVE-2018-1114Undertowundertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service [details]

This update includes the following bug fixes or changes:
IDComponentSummary
Content from issues.jboss.org is not included.JBEAP-14755Possible issue in CloneableCloner.clone
Content from issues.jboss.org is not included.JBEAP-11215ActiveMQARTEMIS-1761 - Log one warning if cluster could not be formed because it's not possible to connect to other cluster node
Content from issues.jboss.org is not included.JBEAP-14534ActiveMQDefaultJMSConnectionFactory not found after switching to elytron and removing picketbox subsystem
Content from issues.jboss.org is not included.JBEAP-14190ActiveMQENTMQBR-1034 - Cannot establish connection between EAP 6 HornetQ and EAP 7 Artemis if connector or acceptor contains any properties
Content from issues.jboss.org is not included.JBEAP-14280ActiveMQENTMQBR-1043 - AMQ119034: Params for management operations must be of the following type: int long double String boolean Map or array thereof but found [B"
Content from issues.jboss.org is not included.JBEAP-14468Build SystemRemove all slf4j dependencies from WildFly (EAP full)
Content from issues.jboss.org is not included.JBEAP-14645CDI / WeldBean discovery in deployment dependencies (modules) fails to inject from static module-alias's exported dependency
Content from issues.jboss.org is not included.JBEAP-14707CLIUnable to pass any attribute to jboss-cli.ps1 script
Content from issues.jboss.org is not included.JBEAP-14479ClusteringMemory leak in Infinispan serialization
Content from issues.jboss.org is not included.JBEAP-7503EEJBJCA-1358 - Container is not cleaning up container-managed JMSContext
Content from issues.jboss.org is not included.JBEAP-14545EJBA Timer will hang forever if the database connection is not available
Content from issues.jboss.org is not included.JBEAP-11601EJBThe fix for WFLY-4625 breaks PolicyContext("javax.security.auth.subject.container") in CXF web service with STS
Content from issues.jboss.org is not included.JBEAP-14561EJBjboss.ejb.default-local-transport-provider missing in appclient mode
Content from issues.jboss.org is not included.JBEAP-13936EJBuse of WildFlyInitialContext with wildfly-config.xml throws javax.naming.NoInitialContextException
Content from issues.jboss.org is not included.JBEAP-14153HibernateHHH-11617 Statement leak in case of "SQLGrammarException: could not extract ResultSet"
Content from issues.jboss.org is not included.JBEAP-14664HibernateHHH-11766 Accessing lazy basic property on entity loaded from 2nd level cache throws exception
Content from issues.jboss.org is not included.JBEAP-14493HibernateHHH-12423 HHH-12392 HHH-12562 Fix regressions related to database schemas
Content from issues.jboss.org is not included.JBEAP-14651HibernateHHH-12507 InsertOrderingWithCompositeTypeAssociation test fails on Oracle due to reserved word
Content from issues.jboss.org is not included.JBEAP-14683HibernateHHH-12508 HHH-12520 Bugs related to second-level/query cache not enabled
Content from issues.jboss.org is not included.JBEAP-14663HibernateHHH-12512 LazyGroupMappedByTestTask fails on Oracle
Content from issues.jboss.org is not included.JBEAP-14480HibernateHHH-12226: EntityNotFoundException for lazy OneToOne association using a derived key [details]
Content from issues.jboss.org is not included.JBEAP-14503HibernateHHH-12439 Merging of new entities can fail depending on cascade order
Content from issues.jboss.org is not included.JBEAP-14519JCA- WFLY-10181 Deadlock for threads executing org.jboss.jca.adapters.jdbc.xa.XAManagedConnectionFactory.isEqual (EAP Full) [details]
Content from issues.jboss.org is not included.JBEAP-14434JCAJBJCA-1370: Disable PoolConfiguration.isPrefill when initialSize is 0 [details]
Content from issues.jboss.org is not included.JBEAP-14616JCAJBJCA-1371 - Deadlock for threads executing org.jboss.jca.adapters.jdbc.xa.XAManagedConnectionFactory.isEqual
Content from issues.jboss.org is not included.JBEAP-14506JCAMySQLValidConnectionChecker swallow a root cause of the exception
Content from issues.jboss.org is not included.JBEAP-14775JMSRegression in Remote JCA scenario with JDBC store after Artemis upgrade
Content from issues.jboss.org is not included.JBEAP-13950JMSARTEMIS-1639 - MDB does no longer receive messages after broker was restarted
Content from issues.jboss.org is not included.JBEAP-14691JMXjboss.as:management-root=server MBean might be filtered on queryName/queryMBean methods
Content from issues.jboss.org is not included.JBEAP-13836JSFCannot inject session bean with @EJB to JSF PhaseListener
Content from issues.jboss.org is not included.JBEAP-14320LoggingLOGMGR-191 - Amend NullPointerException in RegexFilter.isLoggable()
Content from issues.jboss.org is not included.JBEAP-14458Loggingorg.apache.commons.discovery.DiscoveryException: Unable to instantiate implementation class for org.apache.commons.logging.LogFactory
Content from issues.jboss.org is not included.JBEAP-14501MigrationCMTOOL-190 - Server Migration Tool not adding
Content from issues.jboss.org is not included.JBEAP-14661ModulesInvalid Secret Key when using a vault and JDK 1.8.0_171 [details]
Content from issues.jboss.org is not included.JBEAP-14398ModulesModuleClassLoader throw exception InvalidPathException "Illegal char <?> [details]
Content from issues.jboss.org is not included.JBEAP-12374ProductizationFile permissions discrepancy between zip and rpms installation
Content from issues.jboss.org is not included.JBEAP-14297RemotingA connection attempt with correct auth info can fail if a connection attempt with incorrect auth info is in progress at the same time
Content from issues.jboss.org is not included.JBEAP-14604RemotingIllegalStateException: Constructor is unexpectedly inaccessible
Content from issues.jboss.org is not included.JBEAP-14095ScriptsJBOSS_HOME is unset in powershell scripts
Content from issues.jboss.org is not included.JBEAP-13978SecurityExternal CS, PKCS11 can't be configured with externalPath (WFCORE)
Content from issues.jboss.org is not included.JBEAP-13441SecurityExternal CS, PKCS11 can't be configured with externalPath
Content from issues.jboss.org is not included.JBEAP-783SecurityIPv6 address in security realm using Kerberos
Content from issues.jboss.org is not included.JBEAP-14565SecurityJACC is broken after server reload
Content from issues.jboss.org is not included.JBEAP-14225SecurityVerify public API signatures during Elytron build.
Content from issues.jboss.org is not included.JBEAP-14702SecurityWildfly Elytron Tool, location is required even for non-filebased type e.g. PKCS11
Content from issues.jboss.org is not included.JBEAP-14536SecurityNPE in io.undertow.security.impl.BasicAuthenticationMechanism.authenticate when picketbox subsystem removed
Content from issues.jboss.org is not included.JBEAP-14462SecurityNeed to handle a http post method on picketlink sp authentication - test
Content from issues.jboss.org is not included.JBEAP-14585SecurityTest HttpMethodToHtmlTestCase.testPutMethod fails due to regression
Content from issues.jboss.org is not included.JBEAP-14591SecurityWFSSL-9 - SSL Context does not handler intermediate certificates correctly
Content from issues.jboss.org is not included.JBEAP-14467ServerMove all slf4j modules to WildFly Core eap
Content from issues.jboss.org is not included.JBEAP-14698Serverjackson-databind-1872 - NullPointerException in SubTypeValidator.validateSubType when validating Spring interface
Content from issues.jboss.org is not included.JBEAP-14790ServerModule ch.qos.cal10n contains upstream jar
Content from issues.jboss.org is not included.JBEAP-14549ServerUse of relative-to="jboss.domain.base.dir" prevents the host from starting up. [details]
Content from issues.jboss.org is not included.JBEAP-14516Testing/Validation: Adding test in EAT for JBEAP-14505 in order to be tested with all the servers
Content from issues.jboss.org is not included.JBEAP-14641UndertowCodecSessionConfig#findSessionId() can cause an incorrect JSESSIONID response cookie reusing a requested non-existent session id [details]
Content from issues.jboss.org is not included.JBEAP-14689UndertowUNDERTOW-1332 - NullPointerException at HttpServletRequestImpl.getLocalAddr [details]
Content from issues.jboss.org is not included.JBEAP-14603UndertowUNDERTOW-1333 - setContentLength(-1) is not clearing the content length header
Content from issues.jboss.org is not included.JBEAP-14625UndertowUNDERTOW-1336 - access-log rotates to a new file name with an incorrect date string when the rotation happens after restarting the instance [details]
Content from issues.jboss.org is not included.JBEAP-14688Web ConsoleHAL-1455 - Messages Added to a JMS topic is always displayed 0 in the management console
Content from issues.jboss.org is not included.JBEAP-14649Web ConsoleHAL-1457 - Console 'Failed to create security context' if there are no data-sources
Content from issues.jboss.org is not included.JBEAP-14637Web ConsoleHHH-12508 HHH-12520 Web administration console not reporting application status because of NullPointerException when accessing entity-cache resource

Note: This update should only be applied to installer or zip-based installations.

To apply this update using the CLI on Unix-based systems, run the following command from JBOSS_HOME:

bin/jboss-cli.sh "patch apply path/to/jboss-eap-7.1.3-patch.zip"

To apply this update using the CLI on Windows-based systems, run the following command from JBOSS_HOME:

bin\jboss-cli.bat "patch apply path\to\jboss-eap-7.1.3-patch.zip"

These commands will apply the update to the installation that contains the CLI script. Other scenarios and use of the management console are covered in the JBoss EAP 7.1 Patching And Upgrading Guide

Category
Components
Article Type