JBoss Enterprise Application Platform 7.4 Update 6 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 7 have been discontinued and replaced with updates delivered on a repeating schedule.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

For more information see the following Red Hat Knowledgebase articles: Maintenance Release Changes in EAP 6.2+ and Updated Patch Management with EAP 6.2+

This update includes all fixes and changes from JBoss Enterprise Application Platform 7.4 Update 05

Download This content is not included.JBoss Enterprise Application Platform 7.4 Update 6

This update includes fixes for the following security related issues:

IDComponentSummary
CVE-2022-24823Servernetty: world readable temporary file containing sensitive data
CVE-2022-25647Servercom.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson
CVE-2021-44906Serverorg.jboss.hal-hal-parent: minimist: prototype pollution

This update includes the following bug fixes or changes:
IDComponentSummary
Content from issues.jboss.org is not included.JBEAP-23423BatchJBERET-543 - sql/jberet.ddl used for database MariaDB instead of sql/jberet-mysql.ddl
Content from issues.jboss.org is not included.JBEAP-21249ClusteringCNFE ManageableThreadPoolExecutorService from Module "org.infinispan"
Content from issues.jboss.org is not included.JBEAP-18799ClusteringClustering: com.microsoft.sqlserver.jdbc.SQLServerException in SQL Server tests
Content from issues.jboss.org is not included.JBEAP-23510EJBNPE when EJB Database Timer Persistence adjustCreateAutoTimerStatement is called
Content from issues.jboss.org is not included.JBEAP-23522EJBWFLY-16298 - Improve performance related to TimerServiceImpl#scheduledTimerFutures
Content from issues.jboss.org is not included.JBEAP-23622EJBWEJBHTTP-80 - Ejb over http and picketbox stop working with ejb client bom 7.4.3.GA on port 80
Content from issues.jboss.org is not included.JBEAP-16680IOWorkerResourceDefinition.WorkerWriteAttributeHandler implementations incorrectly handle undefined values
Content from issues.jboss.org is not included.JBEAP-23506JCAJBJCA-1362 - NPE from SemaphoreConcurrentLinkedDequeManagedConnectionPool.returnForFrequencyCheck
Content from issues.jboss.org is not included.JBEAP-23502JCAWFLY-16272 - Using an expression in use-java-context for a datasource results in IllegalArgumentException for certain console commands
Content from issues.jboss.org is not included.JBEAP-14177JMSCLI operation list-prepared-transaction-jms-details-as-json returns Object.toString() instead of Json string
Content from issues.jboss.org is not included.JBEAP-23564JPA/HibernateHHH-12338 - Incorrect metamodel for basic collections
Content from issues.jboss.org is not included.JBEAP-23519JSFJSF application undeploy generates SEVERE log entries
Content from issues.jboss.org is not included.JBEAP-3029ManagementReferrals 'throw' does not work correctly for ldap authentication to mgmt console with MS Active Directory
Content from issues.jboss.org is not included.JBEAP-922Migration[Migration operation] [Web to Undertow] truststore - keystore-password does it really needs to be mandatory?
Content from issues.jboss.org is not included.JBEAP-11074RemotingOperation removing http-connector requires full server reload but does not change the server state accordingly
Content from issues.jboss.org is not included.JBEAP-23523RemotingREM3-391 - Remove the lock around Endpoint connection creation
Content from issues.jboss.org is not included.JBEAP-15649ScriptsCheck and consider to put escaped quotes (") back to the -Xloggc in standalone.sh
Content from issues.jboss.org is not included.JBEAP-12448Scriptsstandalone.bat script does not parse JAVA_OPTS containing '
Content from issues.jboss.org is not included.JBEAP-4869SecurityPicketLink - SAMLStatusResponseTypeParser.parseStatus fails on IBM JDK (SAMLSloResponseParserTestCase#testSLOResponseFromSalesforce)
Content from issues.jboss.org is not included.JBEAP-3030SecurityReferrals roles assignment for referral user does not work for LdapExtLoginModule with Active Directory
Content from issues.jboss.org is not included.JBEAP-20152SecuritySASL configuration fails with NPE
Content from issues.jboss.org is not included.JBEAP-3026SecuritySECURITY-975 - Default distinguishedNameAttribute value of LdapExtLoginModule causes not working referrals on MS Active Directory
Content from issues.jboss.org is not included.JBEAP-23621SecurityWFCORE-5650 - Adding management user newly requires reload
Content from issues.jboss.org is not included.JBEAP-15378SecurityPLINK-734 - IdentityUrl element has changed but XSD schema not
Content from issues.jboss.org is not included.JBEAP-15388SecurityStaxUtil should write namespaces firstly for IBM JDK (WSTrustRenewTargetParsingTestCase#testWST_ResponseRenew)
Content from issues.jboss.org is not included.JBEAP-4868SecurityXML processing in SAMLParserUtil fails on IBM JDK (SAMLAssertionParserTestCase#showParserIsFailingWithEmptyAttributeValue)
Content from issues.jboss.org is not included.JBEAP-23570SecurityELY-2308 ELY-2315 - Digest authentication fails for encoded queries
Content from issues.jboss.org is not included.JBEAP-23689SecurityWFCORE-5936 - Ldap authentication using referrals fails on JDK 17 with ApacheDS
Content from issues.jboss.org is not included.JBEAP-23496Securitylibwfssl.so doesn't get autmatically loaded on RHEL 9
Content from issues.jboss.org is not included.JBEAP-18546SecurityInconsistent parameter count between in PicketLink request wrapper
Content from issues.jboss.org is not included.JBEAP-15066ServerCover possible error when host controllers can not connect to domain after creating a rollout plan and restarting the master host controller
Content from issues.jboss.org is not included.JBEAP-21478ServerThe Bouncy Castle bcmail module is missing the java.se dependency
Content from issues.jboss.org is not included.JBEAP-23725Test SuiteTest EAP on RHEL9
Content from issues.jboss.org is not included.JBEAP-23525UndertowUNDERTOW-2069 - Filter.destroy can deadlock with running filter on shutdown
Content from issues.jboss.org is not included.JBEAP-23524UndertowUNDERTOW-2070 - Empty reply from Undertow if sendRedirect is called after setting content length
Content from issues.jboss.org is not included.JBEAP-23581UndertowUNDERTOW-2094 - Bad relative redirect is generated if app is mapped to trailing slash context
Content from issues.jboss.org is not included.JBEAP-23796UndertowUNDERTOW-2116 - java.lang.AssertionError: Content-Encoding header should be defined
Content from issues.jboss.org is not included.JBEAP-12293Web ConsoleCannot add new credential store with credential reference store field
Content from issues.jboss.org is not included.JBEAP-12414Web ConsolePatching via Management Console double-prompts user to restart
Content from issues.jboss.org is not included.JBEAP-12001Web ConsoleUnnecessary add and remove button for main-administrator role.
Content from issues.jboss.org is not included.JBEAP-13587Web ConsoleWhen editing Elytron Policy in Web Console, policy attribute values are getting lost
Content from issues.jboss.org is not included.JBEAP-13766Web ServicesAllow to use remapped elytron application security domain
Content from issues.jboss.org is not included.JBEAP-23190Web ServicesCXF-8655 - Incorrect XSD resolution when the file name is the same in different folders

Installation

Note: This update should only be applied to installer or zip-based installations.

To apply this update using the CLI on Unix-based systems, run the following command from JBOSS_HOME:

bin/jboss-cli.sh "patch apply path/to/jboss-eap-7.4.6-patch.zip"

To apply this update using the CLI on Windows-based systems, run the following command from JBOSS_HOME:

bin\jboss-cli.bat "patch apply path\to\jboss-eap-7.4.6-patch.zip"

These commands will apply the update to the installation that contains the CLI script. Other scenarios and use of the management console are covered in the JBoss EAP 7.4 Patching And Upgrading Guide

Notes

Category
Components
Article Type