Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10386 - Security Advisory
Issued:
2024-11-26
Updated:
2024-11-26

RHSA-2024:10386 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: Red Hat JBoss Enterprise Application Platform 8.0 update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

A security update is now available for Red Hat JBoss Enterprise Application Platform 8.0. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Enterprise Application Platform 8 is a platform for Java applications based on the WildFly application runtime.

This asynchronous patch is an update for Red Hat JBoss Enterprise Application Platform 8.0. JBoss Enterprise Application Platform 8.0 Update 4.1 Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

  • org.keycloak/keycloak-services: Vulnerable Redirect URI Validation Results in Open Redirec [eap-8.0.z] (CVE-2024-8883)

Solution

Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database
settings. For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Application Platform 8.0 for RHEL 9 x86_64
  • JBoss Enterprise Application Platform 8.0 for RHEL 8 x86_64

Fixes

  • BZ - 2312511 - CVE-2024-8883 Keycloak: Vulnerable Redirect URI Validation Results in Open Redirec
  • JBEAP-28488 - List of JIRA resolved in this release.

CVEs

  • CVE-2024-8883

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/8.0/
  • https://access.redhat.com/articles/7090605
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Application Platform 8.0 for RHEL 9

SRPM
eap8-eap-product-conf-parent-800.4.1-1.GA_redhat_00001.1.el9eap.src.rpm SHA-256: 115f1e610e921f3a1775fc052b9dd9e86304065f02108ed03cecab1f46a9542a
eap8-wildfly-8.0.4-3.GA_redhat_00007.1.el9eap.src.rpm SHA-256: 9cb157133bf741d853689b8e50245e3b220b5b9ae6c2bec5fb004e31eed5b147
x86_64
eap8-eap-product-conf-parent-800.4.1-1.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 40f09adc1ba4be461ac2023a783effa1a5d5d240c8bcdcfd883a0171f4583738
eap8-eap-product-conf-wildfly-ee-feature-pack-800.4.1-1.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 8401cab27e161ae1557a264b48fdea64cab6b6c0a30e75cc54d5e2b0d101d1ce
eap8-wildfly-8.0.4-3.GA_redhat_00007.1.el9eap.noarch.rpm SHA-256: 02ff14d2c5ffc6d88ce8e163aa92a5b8ec8afa37f2dce12527948e010bd242ac
eap8-wildfly-java-jdk11-8.0.4-3.GA_redhat_00007.1.el9eap.noarch.rpm SHA-256: 7fd03af0f3d1646eeaecba6bb6f696270780b52bcaa8dda925adf34812dfcd27
eap8-wildfly-java-jdk17-8.0.4-3.GA_redhat_00007.1.el9eap.noarch.rpm SHA-256: 786911b85ce34d5bdf74558ee3960ce7276ac4e05c49813037d7c04ff308bd45
eap8-wildfly-java-jdk21-8.0.4-3.GA_redhat_00007.1.el9eap.noarch.rpm SHA-256: 8f6ca65b92daeeda820ba99aef5b1ac8981b3012491a135c5964fc1566167aa1
eap8-wildfly-modules-8.0.4-3.GA_redhat_00007.1.el9eap.noarch.rpm SHA-256: 6f7bea589604d24b1e67de8a2721837b53f6ab6861bfa726ab28da0dc8905b36

JBoss Enterprise Application Platform 8.0 for RHEL 8

SRPM
eap8-eap-product-conf-parent-800.4.1-1.GA_redhat_00001.1.el8eap.src.rpm SHA-256: 9ca684db4789a60461a5ad1486e300acce709571b5e357d8789cfb4fe429c955
eap8-wildfly-8.0.4-3.GA_redhat_00007.1.el8eap.src.rpm SHA-256: 361c27ebc00b196419369e285c3a96d8b497860beea75e29584f2710fefc309f
x86_64
eap8-eap-product-conf-parent-800.4.1-1.GA_redhat_00001.1.el8eap.noarch.rpm SHA-256: 16e98821d2cbfb52989fc1632db864f2b68df4f17357afae681bc5d63d8bd389
eap8-eap-product-conf-wildfly-ee-feature-pack-800.4.1-1.GA_redhat_00001.1.el8eap.noarch.rpm SHA-256: 8a06da38db814ca57ae4c8876b40b3c1b4e3d6f01b9bbe3fd642adce38b933fe
eap8-wildfly-8.0.4-3.GA_redhat_00007.1.el8eap.noarch.rpm SHA-256: 6279c368cdfb828e07ad475355163c8ee46449d7f2453856402f65701f8f8686
eap8-wildfly-java-jdk11-8.0.4-3.GA_redhat_00007.1.el8eap.noarch.rpm SHA-256: f8094db7e0fed2e26d7d403c8a45f97d55da9e3997f043259540d11a929fb549
eap8-wildfly-java-jdk17-8.0.4-3.GA_redhat_00007.1.el8eap.noarch.rpm SHA-256: 506a2ca960e2a1704302125957e7b317ce2947dfbe921616cf58e1ba45fc3616
eap8-wildfly-java-jdk21-8.0.4-3.GA_redhat_00007.1.el8eap.noarch.rpm SHA-256: 80b16b67b72fd5bbe1a78e65e5a0221b33c91c9c9e0de33b2631ac38930c5e62
eap8-wildfly-modules-8.0.4-3.GA_redhat_00007.1.el8eap.noarch.rpm SHA-256: 058ba927eaaf3d41112acb52623c6ad0608fe2868c4f152932f8fc8bbcd4c1aa

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility