RHSA-2024:10386
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 26 Nov 2024, 19:53
Last modified:02 Jun 2026, 10:02
Vulnerability Summary
Overall Risk (default)
low
24/100 CVSS Score
6.1 MEDIUM
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
26 Nov 2024, 19:53
Published
Vulnerability first disclosed
02 Jun 2026, 10:02
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0 update
CVSS Metrics
- v3.1•MEDIUM•Score: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Systems
- redhat•eap8-eap-product-conf-parent
< 0:800.4.1-1.GA_redhat_00001.1.el8eap | < 0:800.4.1-1.GA_redhat_00001.1.el9eap
- redhat•eap8-eap-product-conf-wildfly-ee-feature-pack
< 0:800.4.1-1.GA_redhat_00001.1.el8eap | < 0:800.4.1-1.GA_redhat_00001.1.el9eap
- redhat•eap8-wildfly
< 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap
- redhat•eap8-wildfly-java-jdk11
< 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap
- redhat•eap8-wildfly-java-jdk17
< 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap
- redhat•eap8-wildfly-java-jdk21
< 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap
- redhat•eap8-wildfly-modules
< 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap
References (11)
- https://access.redhat.com/errata/RHSA-2024:10386
- https://access.redhat.com/security/updates/classification/#moderate
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/8.0/
- https://access.redhat.com/articles/7090605
- https://bugzilla.redhat.com/show_bug.cgi?id=2312511
- https://issues.redhat.com/browse/JBEAP-28488
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10386.json
- https://access.redhat.com/security/cve/CVE-2024-8883
- https://www.cve.org/CVERecord?id=CVE-2024-8883
- https://nvd.nist.gov/vuln/detail/CVE-2024-8883
- https://github.com/keycloak/keycloak/blob/main/services/src/main/java/org/keycloak/protocol/oidc/utils/RedirectUtils.java