How to patch CVE-2022-1259 for WildFly 26.1.3?

143 views
Skip to first unread message

Chiyu

unread,
Jul 2, 2024, 2:11:16 PM7/2/24
to WildFly

Hi, I am trying to find a way to patch CVE-2022-1259 for WildFly 26.1.3, we can't upgrade to 28.0.1 Final that has the fix since we need to stay on Jakarta EE8, is there any way we can patch it ourself and how to I verify the patch.

Thanks.

Jose Socola

unread,
Jul 2, 2024, 5:50:21 PM7/2/24
to Chiyu, WildFly
I think u can try to update undetown module to 2.2.33 version, we have 2.2.28 version in prd environments and works fine.

Screenshot 2024-07-02 at 16.49.05.png


Screenshot 2024-07-02 at 16.43.56.png


Regards,
JS

On Tue, Jul 2, 2024 at 1:11 PM Chiyu <chiyur...@gmail.com> wrote:

Hi, I am trying to find a way to patch CVE-2022-1259 for WildFly 26.1.3, we can't upgrade to 28.0.1 Final that has the fix since we need to stay on Jakarta EE8, is there any way we can patch it ourself and how to I verify the patch.

Thanks.

--
You received this message because you are subscribed to the Google Groups "WildFly" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wildfly+u...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wildfly/9bcd3c52-2e96-43a1-94a0-11de89146fa9n%40googlegroups.com.

Chiyu

unread,
Jul 8, 2024, 5:46:10 PM7/8/24
to WildFly
Thanks for the info I can build WildFly 26.1.3 Final with undertow 2.2.33 Final but I can't find confirmation that 2.2.33 Final contains fix for CVE-2022-1259, is there a place I can find what vulnerabilities is resolved in each undertow build?

Thanks.

Bartosz Baranowski

unread,
Jul 9, 2024, 1:05:59 AM7/9/24
to WildFly

Chiyu

unread,
Jul 9, 2024, 10:07:57 AM7/9/24
to WildFly
Great, just what I'm looking for.

Thanks for the info.
Reply all
Reply to author
Forward
0 new messages