Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:1913 - Security Advisory
Issued:
2024-05-07
Updated:
2024-05-07

RHSA-2024:1913 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Web Server 5.8.0 release and security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat JBoss Web Server 5.8 on Red Hat Enterprise Linux versions 7, 8, and 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 5.8.0 serves as a replacement for Red Hat JBoss Web Server 5.7.8. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section.

Security Fix(es):

  • tomcat: Apache Tomcat: WebSocket DoS with incomplete closing handshake (CVE-2024-23672)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 5 for RHEL 9 x86_64
  • JBoss Enterprise Web Server 5 for RHEL 8 x86_64
  • JBoss Enterprise Web Server 5 for RHEL 7 x86_64

Fixes

  • BZ - 2269608 - CVE-2024-23672 Apache Tomcat: WebSocket DoS with incomplete closing handshake

CVEs

  • CVE-2024-23672

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/documentation/en-us/red_hat_jboss_web_server/5.8/html-single/red_hat_jboss_web_server_5.8_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 5 for RHEL 9

SRPM
jws5-mod_cluster-1.4.5-1.Final_redhat_00001.1.el9jws.src.rpm SHA-256: a9fc79bdf240d6acec3aef074d4256afb55bb6053524bf609f714ba7c1161623
jws5-tomcat-9.0.87-3.redhat_00003.1.el9jws.src.rpm SHA-256: 328ed852e0481101340a8ac0384184439e5b0789b3384d18b77cc92dff920ce0
x86_64
jws5-mod_cluster-1.4.5-1.Final_redhat_00001.1.el9jws.noarch.rpm SHA-256: 78bcd415c55d4d5d1b9c744b10de692668aebeb9b68b1176cb0e80e89eaf0b37
jws5-mod_cluster-tomcat-1.4.5-1.Final_redhat_00001.1.el9jws.noarch.rpm SHA-256: e526468fc803144ed96fa67d2f2679a645f7f4455134875c679804b272d1bdb4
jws5-tomcat-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 35e2ae57f41c66b8b8da019ca0665d82e23d0461d5ec7c74e0d90aa1be4b724a
jws5-tomcat-admin-webapps-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 63e75eb5256f728b75be30411b75a0cd54f3dfd02b0e35cc21794de3ddf17eac
jws5-tomcat-docs-webapp-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: be13276e2ae515ee72162e7da52c778e745a42ddb62174f4a923f9e09389f5ba
jws5-tomcat-el-3.0-api-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 7367e24e077cdae2ba70c75fe6ce498c3659a33af94caa6f45734ea71494edd4
jws5-tomcat-javadoc-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 712f8eef14ccc429dfc2c76ca6e74a842592d18b50de2981f273474251348603
jws5-tomcat-jsp-2.3-api-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 7bcb59ad089e3e5877d30722f99041d439e0125faa3c9ba068e73d481a963398
jws5-tomcat-lib-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 6318c5113a25942b330672139928c3243eff316f8443d71d861034cf7dc3dfb7
jws5-tomcat-selinux-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 789bd75a2e81a4bdbd1b3483436c4ecce6618ef1ba93484102a0b5a5c3825d46
jws5-tomcat-servlet-4.0-api-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 407747ccd2e10225e79df22cec18a920d89038d81ffb62f603a6f447e5537d5a
jws5-tomcat-webapps-9.0.87-3.redhat_00003.1.el9jws.noarch.rpm SHA-256: 1c63c661bbcdc7cb33903bbd487e0bdf1be614c927aafa26063d73ff44abbfa6

JBoss Enterprise Web Server 5 for RHEL 8

SRPM
jws5-mod_cluster-1.4.5-1.Final_redhat_00001.1.el8jws.src.rpm SHA-256: 3364bc1eb49020a48f4c68fee64ccde163dd26ee08e7ba2e73ec1907707e7874
jws5-tomcat-9.0.87-3.redhat_00003.1.el8jws.src.rpm SHA-256: cd56f0a35549952667efb167f38bf3f00fd26b46e33d27b76e5e52e15abd7eba
x86_64
jws5-mod_cluster-1.4.5-1.Final_redhat_00001.1.el8jws.noarch.rpm SHA-256: c4583e894df92ee467dfa60bb07a8d623e62bb652001a03ee6bd3dbe0690d2a6
jws5-mod_cluster-tomcat-1.4.5-1.Final_redhat_00001.1.el8jws.noarch.rpm SHA-256: 3ec417c476ac520d585bafecb1cb44329cd9945e5cd9ee8fe9c01cd3c6ff2e6f
jws5-tomcat-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: d533a16dbf112f18ff91b20421ea1ee925e55962e476f3bec7ec6d28e1aa54b5
jws5-tomcat-admin-webapps-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: 30b113d4a58f1202e76106bb9a87dc727663964cf60e03b0ab505e424084d9db
jws5-tomcat-docs-webapp-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: 656f4b0669a74ea10f383460d31b430775b00838bd362537641c260153b9e14e
jws5-tomcat-el-3.0-api-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: 69f1a4f74b3e094bf6619ef55840e9e47307e3d1d071f81a09b28a6d35242a70
jws5-tomcat-javadoc-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: 8ee77eb2e1e05b3ff1c3bffff0a68947a35c3e3fe219846f65d27e1921d93420
jws5-tomcat-jsp-2.3-api-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: 1732b3b33657e60981c09e3f5bf16e678ba8240a8741dec6710d26f19ae6a1f5
jws5-tomcat-lib-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: 84563ed50559b9e11de7b0534b41609ce8645b6c0f8f982cae6c8e24b46cabd0
jws5-tomcat-selinux-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: 55334dae277c75d7042545d4d605fd658bd50da386b579cb1f0d43cea3579600
jws5-tomcat-servlet-4.0-api-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: fcfe77209d639cb97523ca633a61978b058de40ee27fc13c1f00377ca0baae12
jws5-tomcat-webapps-9.0.87-3.redhat_00003.1.el8jws.noarch.rpm SHA-256: e18e262870836f99d00a3af6092b9a72353d03bebd9b959b31e3d31748805f1d

JBoss Enterprise Web Server 5 for RHEL 7

SRPM
jws5-mod_cluster-1.4.5-1.Final_redhat_00001.1.el7jws.src.rpm SHA-256: 1b9f2cfe5754ec7180006d751c2832c0cb8006876caa6ba5db31e71f97f3de86
jws5-tomcat-9.0.87-3.redhat_00003.1.el7jws.src.rpm SHA-256: 3f069b6d3caa4be3a36f44824409d4fdc285a809bc34a2fbf1b8ece63cc82209
x86_64
jws5-mod_cluster-1.4.5-1.Final_redhat_00001.1.el7jws.noarch.rpm SHA-256: 04675109abb41c09b75b342ece341315e56ba0a9a12c28537929120e59bab610
jws5-mod_cluster-tomcat-1.4.5-1.Final_redhat_00001.1.el7jws.noarch.rpm SHA-256: 9776b0c9f72af7c432e714ae81afe416e3d020381baba9136d23e989f1451f27
jws5-tomcat-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 6b319c3f2c31785200cb983901146cb57ccff2c03d20b6d1685ceb37af6b8c81
jws5-tomcat-admin-webapps-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 9506f1f4fc68b8c6eca3bcf7c1b383b00ec1f8899cdf1dc7a69d53e12e9b3c32
jws5-tomcat-docs-webapp-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 9fb208948d233d2fae2ba92cc928c75e36763b0443308c8a3e07454292924992
jws5-tomcat-el-3.0-api-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 5e078f27dc7452c28f88ff136198532b367c80794195cd5aa10ac6d978a2cf18
jws5-tomcat-java-jdk11-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 01356d2451ff3a6134ea1261331a29f98f3343698d27a3844a49fc6a8f6ded23
jws5-tomcat-java-jdk8-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 42c0a980073a2a924b65d0fdf661fa03f0e9e4c580a316007c1deb7bdcdb3976
jws5-tomcat-javadoc-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 391a0cc7b7a76bb6a2837a7099bc5b787362be7baa2021a3a70e79c9a30b151a
jws5-tomcat-jsp-2.3-api-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: f25ea0aab54a0300c910e29d64dc92d17c81f2444704f6a67d2b8a097bbde671
jws5-tomcat-lib-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 076998f54da5c0cf2b3c8156bc6adea8d039b76317b9739ebf9d5499db6dcc66
jws5-tomcat-selinux-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 1c2351b88c0bf245fd666eabaa86065d816347bc577455efb79d2a51a9cb2d80
jws5-tomcat-servlet-4.0-api-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 1e23dddf392c460310ab97259a6addaced7cd9048c63c2cf5dcf4f5081b58c69
jws5-tomcat-webapps-9.0.87-3.redhat_00003.1.el7jws.noarch.rpm SHA-256: 5df86a3f43d94ec77380e201b1ad75d1d623a6a3b27ce0892f05c5eeebcc8c98

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility