JBoss Enterprise Application Platform 7.4 Update 14 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 7 have been discontinued and replaced with updates delivered on a repeating schedule.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

For more information see the following Red Hat Knowledgebase articles: Maintenance Release Changes in EAP 6.2+ and Updated Patch Management with EAP 6.2+

This update includes all fixes and changes from JBoss Enterprise Application Platform 7.4 Update 13

Download This content is not included.JBoss Enterprise Application Platform 7.4 Update 14

This update includes fixes for the following security related issues:

IDComponentSummary
CVE-2023-2976Serverguava: insecure temporary directory creation
CVE-2023-39410Serveravro: apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK]
CVE-2023-44487Undertownetty-codec-http2: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
CVE-2023-4503Servereap-galleon: custom provisioning creates unsecured http-invoker
CVE-2023-35887Serversshd-common: apache-mina-sshd: information exposure in SFTP server implementations

This update includes the following bug fixes or changes:
IDComponentSummary
This content is not included.JBEAP-25844ActiveMQConfiguration applied on ServerAdd shouldn't apply runtime changes on boot for the sub resources
This content is not included.JBEAP-26039BatchNot possible to add new thread factory to batch-jberet subsystem
This content is not included.JBEAP-25715CDI / WeldThis content is not included.WELD-2755 - Avoid creating duplicate thread groups
This content is not included.JBEAP-26032Clusteringorg.infinispan.commons.CacheException: java.lang.IllegalArgumentException: Only byte[] instances are supported currently!
This content is not included.JBEAP-25743ClusteringHotRod-based session manager requires too many remote operations for ATTRIBUTE granularity sessions
This content is not included.JBEAP-26034ClusteringHotrod : Cache inconsistency
This content is not included.JBEAP-25740ClusteringHotrod-based session manager unnecessary receives server events when near cache is disabled
This content is not included.JBEAP-25617ClusteringThis content is not included.ISPN-15147 - DefaultExecutorFactory can create multiple ThreadGroups
This content is not included.JBEAP-25504Clustering causes sessions to expire prematurely using the HotRod-based HttpSession manager
This content is not included.JBEAP-25683ClusteringExcessive network usage in RHDG during session expiration processing in HSM
This content is not included.JBEAP-26267ClusteringJGRP-2713 - jgroups RouterStubManager race condition that cause one or more gossip router never get reconnected
This content is not included.JBEAP-3583EJBThis content is not included.WFLY-6282 - Exceptions in 2-clusters EJB invocation graceful shutdown tests
This content is not included.JBEAP-25450EJBThis content is not included.JBMAR-254 - JVM crash when passing record to local EJB via remote interface
This content is not included.JBEAP-14932EJBNoSuchObjectException: WFLYEJB0056 ... ConnectException: Connection refused: no further information
This content is not included.JBEAP-25800JCAResource adapters - duplicate resource between attribute and children definitions
This content is not included.JBEAP-25464JMSMigration tool cannot add default module on JMS bridge on EAP 6.4 to EAP 7.4 migration
This content is not included.JBEAP-25906JMSWARN message from Artemis when starting EAP
This content is not included.JBEAP-25595JMSContent from issues.apache.org is not included.ARTEMIS-4427 - MDB reusing Thread is using wrong transactionTimeout
This content is not included.JBEAP-25824JMSThis content is not included.UNDERTOW-2305 - Messaging clients are not load-balanced using Undertow loadbalancer
This content is not included.JBEAP-25746LoggingAlign log message IDs in ControllerLogger with upstream
This content is not included.JBEAP-25573MP MetricsMemory leak on app redeploy
This content is not included.JBEAP-25586MP MetricsMemory leak in MetricCollector
This content is not included.JBEAP-25729ManagementInvalid YAML configuration fails silently
This content is not included.JBEAP-25730ManagementPossible NPE in YAMLExtension for some resource without an add operation
This content is not included.JBEAP-25820ManagementThis content is not included.WFCORE-6505 - Avoid creating duplicate thread groups on server reload
This content is not included.JBEAP-25679ManagementYAML: A resource name can't match an attribute name of this resource
This content is not included.JBEAP-25728ManagementYAML: MapAttributeDefinition not properly processed for existing resources
This content is not included.JBEAP-23744MicroProfileAllow admin-only servers to boot with a config that includes the MicroProfile subsystems removed in base EAP 7.4 [details]
This content is not included.JBEAP-25452RESTfix resteasy / yasson issue with JDK17 record
This content is not included.JBEAP-24111RemotingXNIO NotifierState can cause StackOverflowException when the chain of notifier states becomes problematically big
This content is not included.JBEAP-25559ScriptsAppClientScriptTestCase fails with grep >= 3.8
This content is not included.JBEAP-25828ScriptsThis content is not included.WFCORE-6552 - Windows: WARNING: package com.sun.net.internal.ssl not in java.base
This content is not included.JBEAP-18717SecurityThis content is not included.WFCORE-4296 - Illegal reflective access by org.wildfly.extension.elytron.SSLDefinitions [details]
This content is not included.JBEAP-25718ServerAvoid creating duplicate thread groups on server reload
This content is not included.JBEAP-25680ServerThis content is not included.JANDEX-50 - AnnotationInstance hash collissions degrade indexing processing time
This content is not included.JBEAP-25720TransactionsWFTC-136 Memory leak :reload operation in transaction client
This content is not included.JBEAP-25557UndertowUndertow SSO invalidation fails with UnsupportedOperationException
This content is not included.JBEAP-25833UndertowThis content is not included.UNDERTOW-2316 - Unify InMemorySessionManager getSession() method behavior with DistributableSessionManager
This content is not included.JBEAP-25455UndertowThis content is not included.UNDERTOW-2296 - Wrong type in INCLUDE_MAPPING request attribute
This content is not included.JBEAP-25582UndertowThis content is not included.UNDERTOW-2307 - ScopedAttributeELResolver performance improvement
This content is not included.JBEAP-25735UndertowThis content is not included.UNDERTOW-2313 - NPE occurs in session invalidation if a session creation attempt hits This content is not included.UNDERTOW-1971
This content is not included.JBEAP-25565Web ConsoleThis content is not included.HAL-1884 - EAP Management console does not show credential store and alias in the datasource configuration
This content is not included.JBEAP-25692Web ConsoleThis content is not included.HAL-1908 - "remove" option is seen in "Deployments --> ServerGroups" instead of "undeploy"
This content is not included.JBEAP-25738Web ServicesThis content is not included.JBWS-4389 - Wrong assumption about the Identity's password are all clearpassword

Installation

Note: This update should only be applied to installer or zip-based installations.

To apply this update using the CLI on Unix-based systems, run the following command from JBOSS_HOME:

bin/jboss-cli.sh "patch apply path/to/jboss-eap-7.4.14-patch.zip"

To apply this update using the CLI on Windows-based systems, run the following command from JBOSS_HOME:

bin\jboss-cli.bat "patch apply path\to\jboss-eap-7.4.14-patch.zip"

These commands will apply the update to the installation that contains the CLI script. Other scenarios and use of the management console are covered in the JBoss EAP 7.4 Patching And Upgrading Guide

Notes

Category
Components
Article Type