JBoss Enterprise Application Platform 8.0 Update 2 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 8 have been discontinued and replaced with updates delivered on a repeating schedule.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

This update includes all fixes and changes from JBoss Enterprise Application Platform 8.0 Update 1.1

Download This content is not included.JBoss Enterprise Application Platform 8.0 Update 2

This update includes fixes for the following security related issues:

IDComponentImpactSummary
CVE-2024-1233SecurityModerateeap: JBoss EAP: wildfly-elytron has a SSRF security issue
CVE-2024-1102ServerModeratejberet-core: jberet: jberet-core logging database credentials
CVE-2023-4503ServerModerateeap-galleon: custom provisioning creates unsecured http-invoker
CVE-2023-6236SecurityModerateeap: JBoss EAP: OIDC app attempting to access the second tenant, the user should be prompted to log

This update includes the following bug fixes or changes:

IDComponentSummary
This content is not included.JBEAP-25239A-MQ RAJBoss throws UnknownHostExceptions and XARecovery fails when Connected to an AMQ Cluster in OpenShift
This content is not included.JBEAP-25252A-MQ7This content is not included.ENTMQBR-8489 - Unhandled NullPointerException in JournalTransaction::forget
This content is not included.JBEAP-25230ActiveMQAMQ212051: Invalid concurrent session usage.
This content is not included.JBEAP-25489ActiveMQArtemis is logging warnings during clean shutdown of server in cluster
This content is not included.JBEAP-26036BatchThis content is not included.WFCORE-6592 - Not possible to add new thread factory to batch-jberet subsystem
This content is not included.JBEAP-26691BootableJarBootable JAR deployments cannot use the System.Logger
This content is not included.JBEAP-26953BootableJarBootable jar app on Operator: No deployment content with hash yyy
This content is not included.JBEAP-26846BootableJarorg.wildfly.core:wildfly-jar-boot artifact is missing from the EAP8 manifest
This content is not included.JBEAP-25588CDI / WeldMemory leak on :reload operation
This content is not included.JBEAP-26042ClusteringHotrod : Cache inconsistency
This content is not included.JBEAP-26017ClusteringThis content is not included.ISPN-15310 - Duplicated classes in infinispan-objectfilter-14.0.17.Final-redhat-00002.jar and jackson-core-2.15.2.redhat-00001.jar
This content is not included.JBEAP-26212ClusteringThis content is not included.ISPN-15368 - Eliminate repeatedly created ThreadGroups
This content is not included.JBEAP-26658ClusteringRegression due to SSLHandshakeException affecting HotRod client when connecting to remote Infinispan
This content is not included.JBEAP-25488ClusteringThis content is not included.WFLY-18384 - [CLUSTERING] File containing session data is never shrunk or deleted
This content is not included.JBEAP-26114ClusteringClient fail rate degradation in tests with Oracle database
This content is not included.JBEAP-26112Clustering: java.io.InvalidClassException with ORACLE Data store
This content is not included.JBEAP-26404ClusteringShared distributed session manager triggers duplicate expiration listeners
This content is not included.JBEAP-26325Clusteringmax-active-sessions=-1 causes ISPN000424 error for distributable webapp
This content is not included.JBEAP-25790EJBHotRod calls to remote caches use outdated topology information
This content is not included.JBEAP-26390EJBThis content is not included.EJBCLIENT-531 - Discovery: take static blocklist into account during cluster discovery
This content is not included.JBEAP-25221EJBThis content is not included.WFLY-14769 - Lookup of txn:LocalUserTransaction makes it possible to illegally use UserTransaction in a CMT context
This content is not included.JBEAP-25215InsightsMWTELE-90 - Insights artifacts don't comply with EAP rules for MANIFEST.MF content
This content is not included.JBEAP-26508InsightsUse Bearer token auth instead of Basic token auth
This content is not included.JBEAP-26331InstallerAll page warnings should be displayed in the validation
This content is not included.JBEAP-26066InstallerDuplicated mnemonic key on Security domain screen, Property file option
This content is not included.JBEAP-26206InstallerGUI installer throws NPE on Windows when trying to enter path on non-existing drive for settings.xml
This content is not included.JBEAP-26207InstallerGUI installer throws NPE on Windows when trying to enter invalid path to settings.xml
This content is not included.JBEAP-26274Installerjboss eap installation manager does not handle a zip file
This content is not included.JBEAP-25925Installer[GUI Installer] Add ability for translations to reference other translations
This content is not included.JBEAP-26161Installer[GUI Installer] Certificate security configuration creates unnecessary configuration
This content is not included.JBEAP-26784JCAJCA: make sure WorkManager doesn't relate on jboss-threads executor's blocking API
This content is not included.JBEAP-26751JCAConnector: restore application security configuration
This content is not included.JBEAP-25266JCAThis content is not included.JBJCA-1471 - Prefill pool after returned connection has been destroyed
This content is not included.JBEAP-26220JCAThis content is not included.WFLY-18703 - Misleading error message for XA DataSource class
This content is not included.JBEAP-26507JDRJDR not collecting server manifest.yaml
This content is not included.JBEAP-26490JMS"AMQ229014: Did not receive data from invm:0 within the -1ms connection TTL" occurs due to a race condition
This content is not included.JBEAP-25596JMSThis content is not included.ENTMQBR-8367 - MDB reusing Thread is using wrong transactionTimeout
This content is not included.JBEAP-25942JMXThread's context classloader for ServiceMBeanSupport startService is not application module
This content is not included.JBEAP-26687JPA/HibernateJakartaEE application client: module "org.hibernate" is not added to classpath
This content is not included.JBEAP-25284LoggingThis content is not included.MODULES-439 - Create a delegating LoggerFinder
This content is not included.JBEAP-26026LoggingThis content is not included.WFCORE-6589 - MDC is ignored when using Log4J 2 API
This content is not included.JBEAP-25513MP MetricsMemory leak on app redeploy
This content is not included.JBEAP-26661MigrationConfiguration migration to EAP 8 fails if jgroup authentication is configured in EAP 7.4.x configuration files.
This content is not included.JBEAP-26832MigrationServer Migration Tool cannot recognize EAP 8 Update X
This content is not included.JBEAP-26194ModulesThis content is not included.WFCORE-6697- list-resource-loader-paths fails with MalformedURLException
This content is not included.JBEAP-25694OpenShiftEAP8 env properties overwriting
This content is not included.JBEAP-26694Packaging and InstallingFeature pack is installed even if operation is cancelled
This content is not included.JBEAP-26750Packaging and InstallingManifest file - include some version string in the name field
This content is not included.JBEAP-26290Packaging and InstallingReverting an update doesn't use the cache.
This content is not included.JBEAP-26449Packaging and InstallingUnnecessary fields in .installation/manifest.yaml file of installation manager
This content is not included.JBEAP-24913Packaging and InstallingThis content is not included.WFCORE-6559 - PowerShell support for Prospero integration
This content is not included.JBEAP-26324Packaging and InstallingThis content is not included.WFCORE-6653 - Missing maven-repo-files description on the help of management CLI installer command
This content is not included.JBEAP-25939Packaging and Installing[jboss-eap-installation-manager] Some use cases don't work with the current channel blocklist implementation.
This content is not included.JBEAP-26805Packaging and Installinginstaller-channels.yaml file created by jboss-eap-installation-manager uses wrong property name noStreamStrategy
This content is not included.JBEAP-26022Packaging and Installinglicense.xml has different line endings when provisioned on Windows
This content is not included.JBEAP-26785Packaging and InstallingAdd ability to modify provisioning configuration when installing certain feature packs
This content is not included.JBEAP-27003Packaging and InstallingDifferent manifest content in EAP 8.0.2.GA-CR1 and Maven repository ZIP bit
This content is not included.JBEAP-25770Packaging and InstallingDifferent metadata after Prospero installation on Windows
This content is not included.JBEAP-26480Packaging and InstallingProspero - add a flag to print debug statements in console
This content is not included.JBEAP-26451Packaging and InstallingProspero revert operation doesn't change the installation-channels.yaml file
This content is not included.JBEAP-26402Packaging and Installing[jboss-eap-installation-manager] .installation/.cache/artifacts.txt with non-expected content breaks Prospero
This content is not included.JBEAP-26951Packaging and Installing[jboss-eap-installation-manager] Revert on fresh EAP install brings unexpected changes
This content is not included.JBEAP-26881Packaging and Installing[jboss-eap-installation-manager] When adding feature pack, message about conflicts mentions "update"
This content is not included.JBEAP-26938Packaging and Installing[jboss-eap-installation-manager] When installing XP 5 on top of existing EAP, XP lifecycle notice is not presented to user
This content is not included.JBEAP-26127RESTPredicates not applied correctly to gzip filters
This content is not included.JBEAP-25293RESTRESTEasy StringTextStar provider can produce not-valid output
This content is not included.JBEAP-26037ScriptsThis content is not included.WFCORE-4296 - Illegal reflective access by org.wildfly.extension.elytron.SSLDefinitions when started by ps1 script
This content is not included.JBEAP-26625ScriptsThis content is not included.WFCORE-6531 - standalone.sh and possibly other scripts usage of eval
This content is not included.JBEAP-26354SecurityThis content is not included.ELY-2538 - Provide a possibility for a caching realm to authenticate users with underlying realm when credential verification with cached credential fails
This content is not included.JBEAP-26646SecurityELYWEB-222 - Add a test for single sign on across two apps
This content is not included.JBEAP-26258SecurityThis content is not included.ELY-2589 - Elytron SSO does not expire other application sessions for session invalidation like Undertow SSO promptly following sessionid change
This content is not included.JBEAP-26263ServerEAP core sources contains RH internal certificate installation information
This content is not included.JBEAP-25724ServerGSS (8.0.z) This content is not included.WFCORE-6579 - Use Process Controller log file to capture Host Controller and Managed Servers standard error
This content is not included.JBEAP-26221ServerThis content is not included.WFLY-18765 - Missing Locale parameter while calling toUpperCase and toLowerCase methods
This content is not included.JBEAP-26364TransactionsThis content is not included.WFTC-141 - Wildfly-transaction-client doesn't log that the transaction timeout wasn't set, when the driver returns false.
This content is not included.JBEAP-26648TransactionsRemove the unsupported compensations API
This content is not included.JBEAP-25237TransactionsThis content is not included.WFLY-15609 - There is no cleanup of thread bound transaction timeout override on threads used to run servlets [details]
This content is not included.JBEAP-25880VFSThis content is not included.WFCORE-6524 - Do not duplicate managed deployment in content repository in tmp/vfs/temp directory
This content is not included.JBEAP-25879VFSmanaged deployment in content repository duplicated in tmp/vfs/temp directory

Installation

Archive / zip / installer based installations

Note: This update zip should only be applied to installer or zip-based installations.

See the documentation: JBoss EAP 8.0 update methods

RPM installations

See the documentation: Updating an RPM installation

OpenShift Container installations

Update the containers to use the This content is not included.latest tag., to be current on OpenJDK and RHEL fixes.

Notes

Category
Components
Article Type