JBoss Enterprise Application Platform 7.4 Update 10 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 7 have been discontinued and replaced with updates delivered on a repeating schedule.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

For more information see the following Red Hat Knowledgebase articles: Maintenance Release Changes in EAP 6.2+ and Updated Patch Management with EAP 6.2+

This update includes all fixes and changes from JBoss Enterprise Application Platform 7.4 Update 09

Download This content is not included.JBoss Enterprise Application Platform 7.4 Update 10

This update includes fixes for the following security related issues:

IDComponentSummary
CVE-2023-1108UndertowUNDERTOW-2239 - Infinite loop in SslConduit during close on JDK 11 [details]
CVE-2022-41881Servercodec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS
CVE-2022-45787Serverapache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider
CVE-2022-41854Managementdev-java-snakeyaml: dev-java/snakeyaml: DoS via stack overflow
CVE-2022-1471ServerRESTEASY-3260 - CVE-2022-1471 snakeyaml: Constructor Deserialization Remote Code Execution [details]
CVE-2022-41853Serverhsqldb: Untrusted input may lead to RCE attack
CVE-2022-4492Undertowundertow: Server identity in https connection is not checked by the undertow client [details]
CVE-2023-0482ServerRESTEasy: creation of insecure temp files [details]
CVE-2022-38752Managementsnakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode

This update includes the following bug fixes or changes:
IDComponentSummary
Content from issues.jboss.org is not included.JBEAP-24604ActiveMQArtemis natives no longer being loaded
Content from issues.jboss.org is not included.JBEAP-24405ClusteringISPN-13229 - Memory leak if iteration is used with the internal Infinispan cache API
Content from issues.jboss.org is not included.JBEAP-24441ClusteringWFLY-17149 - Failures due to invalid lambda deserialization should invalidate session
Content from issues.jboss.org is not included.JBEAP-24073EEJBEE-258 - FactoryFinderCache does not properly handle comments in service
Content from issues.jboss.org is not included.JBEAP-24401EJBjava.lang.IllegalArgumentException: No marshaller registered for Java type org.jboss.ejb.client.UUIDSessionID in EAP 7.4
Content from issues.jboss.org is not included.JBEAP-24450EJBStrictMaxPoolDerivedSizeReadHandler incorrectly requires exclusive lock and higher level RBAC perms
Content from issues.jboss.org is not included.JBEAP-24376EJBEJBCLIENT-485 - Set default value for discovery.additional-node-timeout
Content from issues.jboss.org is not included.JBEAP-24157EJBWEJBHTTP-74 - The http ejb client should use the servers hostname for the TLS SNI extension during handshake
Content from issues.jboss.org is not included.JBEAP-23904EJBWFLY-16796 - LocalEjbReceiver response contains ContextData that has been removed on the server side
Content from issues.jboss.org is not included.JBEAP-24371JMSMessaging - Transaction remained in prepared state after failover
Content from issues.jboss.org is not included.JBEAP-24522JMSAMQ172015: Can not connect to XARecoveryConfig
Content from issues.jboss.org is not included.JBEAP-24346ManagementWFCORE-6169 - Disable YAML deserialization in the YAML Configuration Extension
Content from issues.jboss.org is not included.JBEAP-24410ModulesWFCORE-6188 - Eliminate useless locking in ServiceModuleLoader
Content from issues.jboss.org is not included.JBEAP-24443ModulesWFCORE-6199 - JBoss allows duplicate user and local dependencies
Content from issues.jboss.org is not included.JBEAP-24496ModulesWFCORE-6211 - Remove ModuleIdentifier from ServiceModuleLoader.preloadModule
Content from issues.jboss.org is not included.JBEAP-24194RESTRESTEASY-3256 - CDI managed beans do not inject @Context injection targets
Content from issues.jboss.org is not included.JBEAP-24613RPMRHEL7/8 rpms: yum groupinstall jboss-eap7 installing JDK11 instead of JDK8 with EAP 7.4 Update 9
Content from issues.jboss.org is not included.JBEAP-24499RPMEAP 7.4 rpm should Obsoletes: eap7-netty-all-4.1.77-3.Final_redhat_00001.1.el8eap.noarch [details]
Content from issues.jboss.org is not included.JBEAP-24583ScriptsFix enable-elytron-se17.cli script
Content from issues.jboss.org is not included.JBEAP-24254ScriptsJDK17, CLI script to update security doesn't apply to microprofile
Content from issues.jboss.org is not included.JBEAP-23416SecurityJBWS-4251 - Add UsernameToken profile integration with Elytron
Content from issues.jboss.org is not included.JBEAP-23415SecurityWFLY-15598 - No migration path from wildfly-24's picketbox UsersRolesLoginModule to wildfly-25 elytron
Content from issues.jboss.org is not included.JBEAP-24266Securityjbossws-cxf-5.4.x elyron/picketbox support
Content from issues.jboss.org is not included.JBEAP-24367SecurityGetting java.util.ConcurrentModificationException while deploying the application
Content from issues.jboss.org is not included.JBEAP-23166SecurityUNDERTOW-2211 causes forbidden access for anonymous resources access.
Content from issues.jboss.org is not included.JBEAP-24168SecurityNo security domain associated error when using WS-Security username authentication
Content from issues.jboss.org is not included.JBEAP-23682ServerAdapt S3Discovery option for EAP 7.4 and EAP 8.x mixed domains
Content from issues.jboss.org is not included.JBEAP-24498Serverdeny-uncovered-http-methods truncates parsing of web.xml file
Content from issues.jboss.org is not included.JBEAP-24375UndertowUNDERTOW-2214 - Jastow compilation error when mixing EL and scriptlet expressions after UNDERTOW-1319
Content from issues.jboss.org is not included.JBEAP-24415UndertowUNDERTOW-2221 - Undertow can add unwanted semicolon to path parameter when client http request packets are separated in the middle of path parameter
Content from issues.jboss.org is not included.JBEAP-24421UndertowUNDERTOW-2222 - Jastow should use UTF-8 for default URI encoding like Undertow

Installation

Note: This update should only be applied to installer or zip-based installations.

To apply this update using the CLI on Unix-based systems, run the following command from JBOSS_HOME:

bin/jboss-cli.sh "patch apply path/to/jboss-eap-7.4.10-patch.zip"

To apply this update using the CLI on Windows-based systems, run the following command from JBOSS_HOME:

bin\jboss-cli.bat "patch apply path\to\jboss-eap-7.4.10-patch.zip"

These commands will apply the update to the installation that contains the CLI script. Other scenarios and use of the management console are covered in the JBoss EAP 7.4 Patching And Upgrading Guide

Notes

Category
Components
Article Type