JBoss Enterprise Application Platform 8.0 Update 4 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 8 have been discontinued and replaced with updates delivered on a repeating schedule.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

This update includes all fixes and changes from JBoss Enterprise Application Platform 8.0 Update 3.1

Download This content is not included.JBoss Enterprise Application Platform 8.0 Update 4

This update includes fixes for the following security related issues:

IDComponentImpactSummary
CVE-2024-4029ManagementLowwildfly-domain-http: wildfly: No timeout for EAP management interface may lead to Denial of Service (DoS)
CVE-2023-52428SecurityImportantcom.nimbusds/nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
CVE-2024-8698SecurityImportantorg.keycloak/keycloak-saml-core-public: Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak
CVE-2022-34169ServerImportantxalan: OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407)
CVE-2024-41172Web ServicesModerateorg.apache.cxf/cxf-rt-transports-http: unrestricted memory consumption in CXF HTTP clients

This update includes the following bug fixes or changes:

IDComponentSummary
This content is not included.JBEAP-26433ActiveMQJTS - MDB inbound tx branch not rolled back
This content is not included.JBEAP-27615Application ClientThis content is not included.WFLY-18557 - appclient -secmgr should be allowed under Java 21
This content is not included.JBEAP-26062ClusteringHotrod: can't create distributed session for externalization to Infinispan
This content is not included.JBEAP-26658ClusteringRegression due to SSLHandshakeException affecting HotRod client when connecting to remote Infinispan
This content is not included.JBEAP-27254Deployment FrameworkIn Domain mode applications are distributed twice to the domain's servers
This content is not included.JBEAP-26877EJBThis content is not included.WFLY-19303 - EJB remote service requiring cluster instead of using distributable-ejb
This content is not included.JBEAP-27376HibernateContent from hibernate.atlassian.net is not included.HHH-17344 - DB2zDialect NullPointerException
This content is not included.JBEAP-27750HibernateContent from hibernate.atlassian.net is not included.HHH-18506 - Flush performance degradation due to itable stubs
This content is not included.JBEAP-27239InsightsMWTELE-266 - Don't create file upload dir if opted out
This content is not included.JBEAP-27709JMSFixing AddressSettings default values
This content is not included.JBEAP-27541LoggingExcessive DEBUG logging on server startup
This content is not included.JBEAP-27383Maven RepositoryRuntime maven repository not in sync with the final manifest for 2.1
This content is not included.JBEAP-25057MigrationLegacy security domain migration does not cover datasources, iiop-openjdk, resource-adapters subsystems
This content is not included.JBEAP-27205Packaging and InstallingInstaller: channel versions shows empty output
This content is not included.JBEAP-27361Packaging and InstallingApply server candidate phase logs are not saved in log files when using Management CLI
This content is not included.JBEAP-27370Packaging and InstallingDo not allow server apply phase if Management CLI client sessions are still opened
This content is not included.JBEAP-26126RESTRecord is not serialized to JSON
This content is not included.JBEAP-27081SecurityThis content is not included.WFCORE-6834 - wildfly-elytron-integration jar duplicated in server modules
This content is not included.JBEAP-27742ServerThis content is not included.WFCORE-6956 - Wrong endpoint-name if the JBoss server name and 'jboss.node.name' are both provided to the server

Installation

Archive / zip / installer based installations

Note: This update zip should only be applied to installer or zip-based installations.

See the documentation: JBoss EAP 8.0 update methods

RPM installations

See the documentation: Updating an RPM installation

OpenShift Container installations

Update the containers to use the latest tag., to be current on OpenJDK and RHEL fixes.

Notes

Category
Components
Article Type