RHEL 9:Red Hat JBoss Enterprise Application Platform 8.1.8 (RHSA-2026:70229)

high Nessus 插件 ID 348793

简介

远程 Red Hat 主机缺少 Red Hat JBoss Enterprise Application Platform 8.1.8 的一个或多个安全更新。

描述

远程 Redhat Enterprise Linux 9 主机上安装的程序包受到 RHSA-2026:70229 公告中提及的多个漏洞影响。

Red Hat JBoss Enterprise Application Platform 8 是基于 WildFly 应用程序运行时的 Java 应用程序平台。此 Red Hat JBoss Enterprise Application Platform 8.1.8 版本可替换 Red Hat JBoss Enterprise Application Platform 8.1.7,并包含缺陷修复和多项增强。请参阅 Red Hat JBoss Enterprise Application Platform 8.1.8 版本说明以获取有关此版本最重要的缺陷修复和增强功能信息。

安全修复:

* jackson-core: jackson-core: 通过异步 JSON 解析器中不完整的修复造成拒绝服务 [eap-8.1.z] (CVE-2026-68494)

* netty-codec-http2:Netty:通过 SPDY 到 HTTP 编解码器中的内存耗尽导致的拒绝服务 [eap-8.1.z] (CVE-2026-56745)

* netty-handler:Netty:通过 OpenSSL 客户端路径错误配置导致的 TLS 主机名验证绕过 [eap-8.1.z] (CVE-2026-62243)

* bcpg-jdk18on:Bouncy Castle for Java:未绑定 OpenPGP 用户属性子数据包长度造成的拒绝服务 [eap-8.1.z] (CVE-2026-59649)

* jackson-databind: jackson-databind: 可对忽略的属性进行意外修改 [eap-8.1.z] (CVE-2026-54515)

* jackson-databind: jackson-databind: 通过不当处理@JsonUnwrapped属性导致权限升级 [eap-8.1.z] (CVE-2026-59889)

* netty-codec-dns:netty:通过域名畸形的 DNS 记录解码器中的内存泄漏造成拒绝服务 [eap-8.1.z] (CVE-2026-73508)

* jboss-eap.1-runtime-maven-repository.zip:jackson-core:异步 JSON 解析器中不完整的修复导致拒绝服务 [eap-8.1.z] (CVE-2026-68494)

* jboss-eap-runtime-maven-repository.zip:jackson-core:异步 JSON 解析器中不完整的修复导致拒绝服务 [eap-8.1.z] (CVE-2026-68494)

* bcprov-jdk18on:不受限制的 PGP AEAD 区块大小导致预认证资源耗尽 [eap-8.1.z] (CVE-2026-3505)

* brace-expansion: brace-expansion: 通过不受限制的中间数组造成的拒绝服务 [eap-8.1.z] (CVE-2026-69152)

* netty-codec-http: Netty:netty-codec-http 中的内存耗尽(解压缩炸弹)[eap-8.1.z] (CVE-2026-59899)

* netty-codec-http:Netty:安全控制绕过允许通过空源标头进行未经授权的请求 [eap-8.1.z] (CVE-2026-56746)

* netty-codec-http:Netty:通过 SPDY 到 HTTP 编解码器中的内存耗尽导致的拒绝服务 [eap-8.1.z] (CVE-2026-56745)

* netty-codec-http:Netty:通过 SPDY SETTINGS 帧处理拒绝服务 [eap-8.1.z] (CVE-2026-55831)

* netty-codec-http:Netty:通过 SPDY 标头解压缩放大的拒绝服务 [eap-8.1.z] (CVE-2026-55833)

* jackson-databind: jackson-databind:安全绕过允许任意代码执行 [eap-8.1.z] (CVE-2026-54513)

* jackson-databind: jackson-databind:通过 PolymorphicTypeValidator 绕过的任意代码执行 [eap-8.1.z] (CVE-2026-54512)

* undertow-core:Undertow:通过超大区块大小位重叠走私 HTTP 请求 [eap-8.1.z] (CVE-2026-14180)

* artemis-server: artemis-server: 通过 channel0 上的 CORE SUBSCRIBE_TOPOLOGY_V2泄露预认证拓扑 [eap-8.1.z] (CVE-2026-49363)

* undertow-websockets-jsr:undertow:带有任何@OnMessage方法的 @ServerEndpoint 类的 websocket 端点上的 Pre-Auth DoS [eap-8.1.z] (CVE-2026-15565)

* wildfly-iiop-openjdk:Wildfly:IIOP 监听器上的预认证拒绝服务 [eap-8.1.z] (CVE-2026-15567)

* cxf-rt-transports-jms:Apache CXF:通过不受信任的 JMS 配置执行任意代码 [eap-8.1.z] (CVE-2026-50632)

* cxf-core:Apache CXF:由于缺少 JAXP 强化,通过带外外部实体解析造成信息泄露 [eap-8.1.z] (CVE-2026-49875)

* wildfly-elytron-asn1:在 WildFly Elytron ASN.1 DERDecoder 中,通过特别构建的 DER 负载进行无限内存分配 [eap-8.1.z] (CVE-2026-10832)

* cxf-rt-transports-jms:Apache CXF:通过不受信任的 JMS 配置进行的远程代码执行 [eap-8.1.z] (CVE-2026-44417)

* wildfly-elytron-realm-token:EAP 的 elytron oauth2 中的参数注入 [eap-8.1.z] (CVE-2026-85511)

* jakarta.faces:mojarra:通过 ui:include 中的 EL 注入,EAP JSF 应用程序中未经身份验证的 RCE [eap-8.1.z] (CVE-2026-46581)

* wildfly-iiop-openjdk:EAP 的 IIOP 名称服务缺少认证会导致 MITM 或 DoS [eap-8.1.z] (CVE-2026-15563)

* jboss-remoting: jboss-remoting:MessageReader 中的整数溢出导致预先认证拒绝服务 [eap-8.1.z] (CVE-2026-15562)

* undertow-core:通过 EAP 的 Undertow 中分块拖尾片中的缺少限制造成 OOM [eap-8.1.z] (CVE-2026-15561)

* openjdk-orb:通过 EAP 中的 IIOP 加载未经身份验证的类 [eap-8.1.z] (CVE-2026-15560)

* artemis-server:通过缺少认证进行的 Apache Artemis 会话劫持 [eap-8.1.z] (CVE-2026-57967)

* wildfly-clustering-infinispan-marshalling:通过 Unfiltered River Unmarshaller 的 Jboss 反序列化 RCE [eap-8.1.z] (CVE-2026-15555)

* undertow-core: undertow:通过 AJP ssl_cert/is_ssl 伪造绕过身份验证 [eap-8.1.z] (CVE-2026-15554)

* jgroups:通过 jgroups 欺骗泄漏 Artemis 群集密码 [eap-8.1.z] (CVE-2026-49364)

* artemis-server:artemis 核心协议允许未经认证的队列创建 [eap-8.1.z] (CVE-2026-49362)

* artemis-server:Red Hat EAP 中的 artemis 消息处理程序默认允许反序列化 [eap-8.1.z] (CVE-2026-86404)

* undertow-core: undertow:通过 WebSocket permessage-deflate 处理造成拒绝服务 [eap-8.1.z] (CVE-2026-5680)

有关上述安全问题的更多详细信息,包括其影响、CVSS 得分、致谢,以及其他相关信息,请参阅列于“参考”部分的 CVE 页面。

Tenable 已直接从 Red Hat Enterprise Linux 安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

依据 RHSA-2026:70229 中的指南更新 RHEL Red Hat JBoss Enterprise Application Platform 8.1.8 程序包。

另见

https://access.redhat.com/articles/7137769

https://access.redhat.com/errata/RHSA-2026:70229

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2455350

https://bugzilla.redhat.com/show_bug.cgi?id=2458638

https://bugzilla.redhat.com/show_bug.cgi?id=2477930

https://bugzilla.redhat.com/show_bug.cgi?id=2477945

https://bugzilla.redhat.com/show_bug.cgi?id=2478013

https://bugzilla.redhat.com/show_bug.cgi?id=2480601

https://bugzilla.redhat.com/show_bug.cgi?id=2480637

https://bugzilla.redhat.com/show_bug.cgi?id=2480638

https://bugzilla.redhat.com/show_bug.cgi?id=2480729

https://bugzilla.redhat.com/show_bug.cgi?id=2483131

https://bugzilla.redhat.com/show_bug.cgi?id=2483133

https://bugzilla.redhat.com/show_bug.cgi?id=2483135

https://bugzilla.redhat.com/show_bug.cgi?id=2483136

https://bugzilla.redhat.com/show_bug.cgi?id=2483138

https://bugzilla.redhat.com/show_bug.cgi?id=2483140

https://bugzilla.redhat.com/show_bug.cgi?id=2484703

https://bugzilla.redhat.com/show_bug.cgi?id=2488304

https://bugzilla.redhat.com/show_bug.cgi?id=2488309

https://bugzilla.redhat.com/show_bug.cgi?id=2490628

https://bugzilla.redhat.com/show_bug.cgi?id=2491620

https://bugzilla.redhat.com/show_bug.cgi?id=2492010

https://bugzilla.redhat.com/show_bug.cgi?id=2492015

https://bugzilla.redhat.com/show_bug.cgi?id=2492016

https://bugzilla.redhat.com/show_bug.cgi?id=2492627

https://bugzilla.redhat.com/show_bug.cgi?id=2494771

https://bugzilla.redhat.com/show_bug.cgi?id=2500653

https://bugzilla.redhat.com/show_bug.cgi?id=2503101

https://bugzilla.redhat.com/show_bug.cgi?id=2503103

https://bugzilla.redhat.com/show_bug.cgi?id=2505422

https://bugzilla.redhat.com/show_bug.cgi?id=2505911

https://bugzilla.redhat.com/show_bug.cgi?id=2507482

https://bugzilla.redhat.com/show_bug.cgi?id=2510195

https://bugzilla.redhat.com/show_bug.cgi?id=2510722

https://bugzilla.redhat.com/show_bug.cgi?id=2511026

https://bugzilla.redhat.com/show_bug.cgi?id=2515377

https://bugzilla.redhat.com/show_bug.cgi?id=2521309

https://issues.redhat.com/browse/JBEAP-32314

https://issues.redhat.com/browse/JBEAP-32869

https://issues.redhat.com/browse/JBEAP-33162

https://issues.redhat.com/browse/JBEAP-33185

https://issues.redhat.com/browse/JBEAP-33236

https://issues.redhat.com/browse/JBEAP-33237

https://issues.redhat.com/browse/JBEAP-33288

https://issues.redhat.com/browse/JBEAP-33363

https://issues.redhat.com/browse/JBEAP-33405

https://issues.redhat.com/browse/JBEAP-33409

https://issues.redhat.com/browse/JBEAP-33413

https://issues.redhat.com/browse/JBEAP-33449

https://issues.redhat.com/browse/JBEAP-33459

https://issues.redhat.com/browse/JBEAP-33501

https://issues.redhat.com/browse/JBEAP-33580

https://issues.redhat.com/browse/JBEAP-33616

https://issues.redhat.com/browse/JBEAP-33640

https://issues.redhat.com/browse/JBEAP-33683

https://issues.redhat.com/browse/JBEAP-33848

https://issues.redhat.com/browse/JBEAP-33871

https://issues.redhat.com/browse/JBEAP-33904

https://issues.redhat.com/browse/JBEAP-33925

https://issues.redhat.com/browse/JBEAP-33967

https://issues.redhat.com/browse/JBEAP-33968

https://issues.redhat.com/browse/JBEAP-33973

https://issues.redhat.com/browse/JBEAP-34018

https://issues.redhat.com/browse/JBEAP-34095

https://issues.redhat.com/browse/JBEAP-34096

https://issues.redhat.com/browse/JBEAP-34111

https://issues.redhat.com/browse/JBEAP-34161

https://issues.redhat.com/browse/JBEAP-34222

https://issues.redhat.com/browse/JBEAP-34521

http://www.nessus.org/u?29b6d808

http://www.nessus.org/u?4f7c1c91

http://www.nessus.org/u?f66ce2ca

插件详情

严重性: High

ID: 348793

文件名: redhat-RHSA-2026-70229.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/9/22

最近更新时间: 2026/9/22

支持的传感器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Medium

分数: 6.9

百分位: 96.81

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Critical

基本分数: 10

时间分数: 7.8

矢量: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-49875

CVSS v3

风险因素: Critical

基本分数: 9.8

时间分数: 8.8

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

风险因素: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS 分数来源: CVE-2026-68494

漏洞信息

CPE: cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-ra, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-rt, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-services, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-tools, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-artemis-wildfly-integration, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-jmail, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-pg, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-pkix, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-prov, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-util, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle, p-cpe:/a:redhat:enterprise_linux:eap8-codemodel, p-cpe:/a:redhat:enterprise_linux:eap8-cryptacular, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-parent, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-wildfly-ee-feature-pack, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-core, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-envers, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate, p-cpe:/a:redhat:enterprise_linux:eap8-httpcomponents-asyncclient, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-spi, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-deployers-common, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-jdbc, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-validator, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-core, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-databind, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformat-yaml, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformats-text, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jdk8, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jsr310, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-base, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-json-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-providers, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-module-jakarta-xmlbind-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-base, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-java8, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-xml-bind-api, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-core, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-jxc, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-runtime, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-xjc, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb, p-cpe:/a:redhat:enterprise_linux:eap8-jaxbintros, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-logging, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-remoting, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-api, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-common-tools, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-jaxws-undertow-httpspi, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-spi, p-cpe:/a:redhat:enterprise_linux:eap8-jsf-impl, p-cpe:/a:redhat:enterprise_linux:eap8-log4j, p-cpe:/a:redhat:enterprise_linux:eap8-neethi, p-cpe:/a:redhat:enterprise_linux:eap8-netty-buffer, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-dns, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-http, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-socks, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec, p-cpe:/a:redhat:enterprise_linux:eap8-netty-common, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler-proxy, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver-dns, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-classes-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-unix-common, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport, p-cpe:/a:redhat:enterprise_linux:eap8-netty, p-cpe:/a:redhat:enterprise_linux:eap8-nimbus-jose-jwt, p-cpe:/a:redhat:enterprise_linux:eap8-parsson, p-cpe:/a:redhat:enterprise_linux:eap8-relaxng-datatype, p-cpe:/a:redhat:enterprise_linux:eap8-rngom, p-cpe:/a:redhat:enterprise_linux:eap8-saaj-impl, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j-api, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j, p-cpe:/a:redhat:enterprise_linux:eap8-txw2, p-cpe:/a:redhat:enterprise_linux:eap8-undertow, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron-tool, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk17, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk21, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-javadocs, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-ws-commons-xmlschema, p-cpe:/a:redhat:enterprise_linux:eap8-xml-security, p-cpe:/a:redhat:enterprise_linux:eap8-xsom

必需的 KB 项: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/9/22

漏洞发布日期: 2026/4/15

参考资料信息

CVE: CVE-2026-10832, CVE-2026-14180, CVE-2026-15554, CVE-2026-15555, CVE-2026-15560, CVE-2026-15561, CVE-2026-15562, CVE-2026-15563, CVE-2026-15565, CVE-2026-15567, CVE-2026-3505, CVE-2026-44417, CVE-2026-46581, CVE-2026-49362, CVE-2026-49363, CVE-2026-49364, CVE-2026-49875, CVE-2026-50632, CVE-2026-54512, CVE-2026-54513, CVE-2026-54515, CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56746, CVE-2026-5680, CVE-2026-57967, CVE-2026-59649, CVE-2026-59889, CVE-2026-59899, CVE-2026-62243, CVE-2026-68494, CVE-2026-69152, CVE-2026-73508, CVE-2026-85511, CVE-2026-86404

CWE: 120, 15, 184, 190, 290, 295, 306, 409, 444, 502, 611, 770, 772, 807, 829, 915, 94

RHSA: 2026:70229