JBoss Enterprise Application Platform 8.0 Update 2.1 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 8 have been discontinued and replaced with updates delivered on a repeating schedule.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

This update includes all fixes and changes from JBoss Enterprise Application Platform 8.0 Update 2

Download This content is not included.JBoss Enterprise Application Platform 8.0 Update 2.1

This update includes fixes for the following security related issues:

IDComponentImpactSummary
CVE-2023-51775SecurityModeratejose4j: denial of service via specially crafted JWE
CVE-2024-5971ServerImportantundertow: response write hangs in case of Java 17 TLSv1.3 NewSessionTicket
CVE-2024-3653UndertowLowundertow: LearningPushHandler can lead to remote memory DoS attacks
CVE-2024-27316UndertowModerateHTTP-2: httpd: CONTINUATION frames DoS

This update includes the following bug fixes or changes:

IDComponentSummary
This content is not included.JBEAP-26479HibernateContent from hibernate.atlassian.net is not included.HHH-17106 - Varchar(1) column for Java Enum fails with ClassCastException
This content is not included.JBEAP-26319HibernateContent from hibernate.atlassian.net is not included.HHH-17380 - Persisting an entity with a non generated id and @MapsId throws PropertyValueException
This content is not included.JBEAP-27265HibernateContent from hibernate.atlassian.net is not included.HHH-17400 - JdbcSQLSyntaxErrorException when using SELECT DISTINCT with ORDER BY on primary key of joined entity
This content is not included.JBEAP-26304HibernateContent from hibernate.atlassian.net is not included.HHH-17405 - Cannot resolve path of generic mapped-superclass association path
This content is not included.JBEAP-26128HibernateContent from hibernate.atlassian.net is not included.HHH-17445 - Subquery correlated path expressions do not work with nullness predicates
This content is not included.JBEAP-26303HibernateContent from hibernate.atlassian.net is not included.HHH-17491 - UnknownEntityTypeException thrown when multiple subclasses define an attribute with the same name and one is a MappedSuperclass
This content is not included.JBEAP-26360HibernateContent from hibernate.atlassian.net is not included.HHH-17606 - Cannot resolve path of nested generic mapped-superclass joins
This content is not included.JBEAP-26357HibernateContent from hibernate.atlassian.net is not included.HHH-17623 - Ordering collection @OrderBy based on association fails
This content is not included.JBEAP-26470HibernateContent from hibernate.atlassian.net is not included.HHH-17670 - NPE in FromClause#findTableGroup
This content is not included.JBEAP-26855HibernateContent from hibernate.atlassian.net is not included.HHH-17734 - "Hibernate should prioritize provider_class over datasource" on EAP 8.x
This content is not included.JBEAP-26819JPA/HibernateContent from hibernate.atlassian.net is not included.HHH-17705 - NullPointerException during enhancement when using the default BytecodeProvider in Wildfly
This content is not included.JBEAP-25832UndertowThis content is not included.UNDERTOW-2332 - Requesting deployment overlay may results in ConnectionClosedException
This content is not included.JBEAP-26974UndertowThis content is not included.UNDERTOW-2374 - At Http2ReceiveListener.checkRequestHeaders do not check path chars when unescaped characters are allowed
This content is not included.JBEAP-26775UndertowThis content is not included.UNDERTOW-2347 - Undertow client must send either http/1.1 or both http/1.1 and h2 in SSL ClientHello handshake message
This content is not included.JBEAP-26975UndertowThis content is not included.UNDERTOW-2351 - NullPointerException on flawed WebSockets war deployment[
This content is not included.JBEAP-26991UndertowThis content is not included.UNDERTOW-2378 - Adjust properly session timeout also in case when custom auth mechanisms are used
This content is not included.JBEAP-27015UndertowThis content is not included.UNDERTOW-2383 - Canonicalized query string in redirect location can break included links
This content is not included.JBEAP-27063UndertowThis content is not included.UNDERTOW-2389/2385 - DefaultByteBufferPool leaks buffers for released threads [details]
This content is not included.JBEAP-26755Web SocketsThis content is not included.UNDERTOW-2354 - Bootstrap$WebSocketListener.contextDestroyed throws NPE after application start up error [details]

Installation

Archive / zip / installer based installations

Note: This update zip should only be applied to installer or zip-based installations.

See the documentation: JBoss EAP 8.0 update methods

RPM installations

See the documentation: Updating an RPM installation

OpenShift Container installations

Update the containers to use the This content is not included.latest tag., to be current on OpenJDK and RHEL fixes.

Notes

Category
Components
Article Type