Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0371 - Security Advisory
Issued:
2025-01-16
Updated:
2025-01-29

RHSA-2025:0371 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Enterprise Application Platform 8.0 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

A security update is now available for Red Hat JBoss Enterprise Application Platform 8.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Enterprise Application Platform 8 is a platform for Java applications based on the WildFly application runtime.

This asynchronous patch is an update for Red Hat JBoss Enterprise Application Platform 8.0 update 5. See Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

  • org.hornetq/hornetq-core-client: Arbitrarily overwrite files or access sensitive information (CVE-2024-51127)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Application Platform 8.0 for RHEL 9 x86_64
  • JBoss Enterprise Application Platform 8.0 for RHEL 8 x86_64

Fixes

  • BZ - 2323697 - CVE-2024-51127 hornetq-core-client: Arbitrarily overwrite files or access sensitive information

CVEs

  • CVE-2024-51127

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/8.0/
  • https://access.redhat.com/articles/7100137
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Application Platform 8.0 for RHEL 9

SRPM
eap8-eap-product-conf-parent-800.5.1-1.GA_redhat_00001.1.el9eap.src.rpm SHA-256: e4d56e4464f2e54f9d8d063927b0e1e0727e734e7c7465105137168a48506b35
eap8-hornetq-2.4.11-1.Final_redhat_00001.1.el9eap.src.rpm SHA-256: 5509645d0222f5723654d7cf69d7fbba9344bb8ccd2256cbb877cbc9f0004b60
eap8-jgroups-5.2.23-2.Final_redhat_00001.1.el9eap.src.rpm SHA-256: bbde5e7cf9ca808eeacd790a301b101f7fe707eadb5e42d5a6a021e025c266e9
eap8-wildfly-8.0.5-5.GA_redhat_00004.1.el9eap.src.rpm SHA-256: 1e42ce34daad7a27a4c304cc51dd8ffc0873814c5f524b4430b9f8b217f0fa83
x86_64
eap8-eap-product-conf-parent-800.5.1-1.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: d061e2abc1c698ba4a31f6f624c23ddaafdf2ee8f4b0a83dea720b0e59baa603
eap8-eap-product-conf-wildfly-ee-feature-pack-800.5.1-1.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 1657fc36c9047102346a332edf094213a585d9a2eeb9b8400e24074040fce370
eap8-hornetq-2.4.11-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: f82312a67f5b4faab9ba3a6d51006645b01c023bc227f8360635cab7565d7742
eap8-hornetq-commons-2.4.11-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 93e6c68658d32ff13d64cad2a1fc86d5399fb6a8984d50bf888c425706dfdfdb
eap8-hornetq-core-client-2.4.11-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 3a8864ffebe849a621a44878221f84be8302bc811c8b66c3e1b723b85f634b0d
eap8-hornetq-jakarta-client-2.4.11-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 9d0d66398969a286f879fe50d730aa280d2187b110dcbec70c7fe4ed7bc1b552
eap8-jgroups-5.2.23-2.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: b5e99504ff0c2ee9fc90568c435beadab13e36706d3a44aa75269135e3e6fb80
eap8-wildfly-8.0.5-5.GA_redhat_00004.1.el9eap.noarch.rpm SHA-256: 74c78b3b77337fd9b7b11d5ba977512931269594a1dc2f3299615c13082d8fac
eap8-wildfly-java-jdk11-8.0.5-5.GA_redhat_00004.1.el9eap.noarch.rpm SHA-256: afe35b5e837f542f5e249aa374e044a9bab27370d638bf1c5eb614e3c6ed3adc
eap8-wildfly-java-jdk17-8.0.5-5.GA_redhat_00004.1.el9eap.noarch.rpm SHA-256: 7dbff203b0437313cc481c55daf44c91283dd490a706d65703cf5520310537de
eap8-wildfly-java-jdk21-8.0.5-5.GA_redhat_00004.1.el9eap.noarch.rpm SHA-256: c76c8daaac70ff27a3434835153f6b2117db5d554b60f54cc1fe6171a0fcd378
eap8-wildfly-modules-8.0.5-5.GA_redhat_00004.1.el9eap.noarch.rpm SHA-256: b126fc45def34ccaead9b21f0bb6bc6bb7f547be02b94f71b56cf15dd39594f6

JBoss Enterprise Application Platform 8.0 for RHEL 8

SRPM
eap8-eap-product-conf-parent-800.5.1-1.GA_redhat_00001.1.el8eap.src.rpm SHA-256: 6e6fda221baf2209c970e6aa2ef9b3c9c7e6e39e2741166126d1e29875aeac0f
eap8-hornetq-2.4.11-1.Final_redhat_00001.1.el8eap.src.rpm SHA-256: 5ffbaa3563d94d0b6d549ac5d120990bb35e472c52a676b53df9f4f8c2ec7823
eap8-jgroups-5.2.23-2.Final_redhat_00001.1.el8eap.src.rpm SHA-256: 2c7cdbf54bc19f2d0f8da4a1818bc0ad154affacdcaae90476ffc3df7d5ccc8c
eap8-wildfly-8.0.5-5.GA_redhat_00004.1.el8eap.src.rpm SHA-256: 5fc773b3b460887d6ace3569fb056f1f15a22e3fca9d3d120a22197052ab08d1
x86_64
eap8-eap-product-conf-parent-800.5.1-1.GA_redhat_00001.1.el8eap.noarch.rpm SHA-256: 1c703581d54225dc786cabd5bb1274c45eff931cd982a4fa5c7c81e6a4646227
eap8-eap-product-conf-wildfly-ee-feature-pack-800.5.1-1.GA_redhat_00001.1.el8eap.noarch.rpm SHA-256: e04c30298f123f4e023cbaffb2dbf79663046fdec29d882289bce9558d7088b9
eap8-hornetq-2.4.11-1.Final_redhat_00001.1.el8eap.noarch.rpm SHA-256: 52a89ec824f23ba0de9bc6376eab719844ed5c1c5d8c1470815ecd240ff50358
eap8-hornetq-commons-2.4.11-1.Final_redhat_00001.1.el8eap.noarch.rpm SHA-256: 21584580ce9421bea98b222e912b8da253217919dd0a4065a10c81fa5e6df37b
eap8-hornetq-core-client-2.4.11-1.Final_redhat_00001.1.el8eap.noarch.rpm SHA-256: bce3f17543ecf7e8894685cb7e7c568997237b329a2947147fc98b13e67c1b5d
eap8-hornetq-jakarta-client-2.4.11-1.Final_redhat_00001.1.el8eap.noarch.rpm SHA-256: 9cfac956612b42c37706d546d758eaf0be0ba58d3dbb02e751cf937abd2d0794
eap8-jgroups-5.2.23-2.Final_redhat_00001.1.el8eap.noarch.rpm SHA-256: 9bb39acc4e253d2693c11603270e2072ccf341f71010a9e4bb96b0be5dbe0b9d
eap8-wildfly-8.0.5-5.GA_redhat_00004.1.el8eap.noarch.rpm SHA-256: 4577cd40c2bc253fa6309cd10bb59becde31d4b5169a96464630e00d64b3285f
eap8-wildfly-java-jdk11-8.0.5-5.GA_redhat_00004.1.el8eap.noarch.rpm SHA-256: eeb2bec43adbb5d7c21c11848f2ead9484c5574663c4ef5b89c42491a394509f
eap8-wildfly-java-jdk17-8.0.5-5.GA_redhat_00004.1.el8eap.noarch.rpm SHA-256: 08d7ac50fb2525cd547fd2eece7b688d12a24f2c227cdb7bf3cbe294897451b7
eap8-wildfly-java-jdk21-8.0.5-5.GA_redhat_00004.1.el8eap.noarch.rpm SHA-256: 713744449ef7100e1fec01bce9e2ce7b3fbdd84ac9121a0b6c9cd4ec29115546
eap8-wildfly-modules-8.0.5-5.GA_redhat_00004.1.el8eap.noarch.rpm SHA-256: f3cb11553137a6a6084bcc11639fb01bc47267419e6c2330bd4e1761cce1f4df

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility