Show plain JSON{"affected_release": [{"advisory": "RHSA-2021:3660", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.4", "product_name": "EAP 7.4.1 release", "release_date": "2021-09-23T00:00:00Z"}, {"advisory": "RHSA-2021:2755", "cpe": "cpe:/a:redhat:jbosseapxp", "impact": "moderate", "package": "velocity", "product_name": "Red Hat EAP-XP 2.0.0 via EAP 7.3.x base", "release_date": "2021-07-15T00:00:00Z"}, {"advisory": "RHSA-2021:2210", "cpe": "cpe:/a:redhat:jbosseapxp", "impact": "moderate", "package": "velocity", "product_name": "Red Hat EAP-XP via EAP 7.3.x base", "release_date": "2021-06-02T00:00:00Z"}, {"advisory": "RHSA-2021:3140", "cpe": "cpe:/a:redhat:jboss_fuse:7", "impact": "moderate", "package": "velocity", "product_name": "Red Hat Fuse 7.9", "release_date": "2021-08-11T00:00:00Z"}, {"advisory": "RHSA-2021:4918", "cpe": "cpe:/a:redhat:integration:1", "impact": "moderate", "package": "velocity", "product_name": "Red Hat Integration", "release_date": "2021-12-02T00:00:00Z"}, {"advisory": "RHSA-2021:4767", "cpe": "cpe:/a:redhat:camel_quarkus:2.2", "impact": "moderate", "package": "velocity", "product_name": "Red Hat Integration Camel Quarkus 2", "release_date": "2021-11-23T00:00:00Z"}, {"advisory": "RHSA-2021:2051", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3", "impact": "moderate", "package": "velocity", "product_name": "Red Hat JBoss Enterprise Application Platform 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2025:1746", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7", "package": "eap7-resteasy-0:3.0.27-1.Final_redhat_00001.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1746", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7", "package": "eap7-velocity-0:1.7.0-3.redhat_00006.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-hal-console-0:3.2.17-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-jackson-annotations-0:2.10.4-2.redhat_00004.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-jackson-core-0:2.10.4-2.redhat_00004.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-jackson-databind-0:2.10.4-4.redhat_00004.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-jackson-jaxrs-providers-0:2.10.4-2.redhat_00004.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-jackson-modules-base-0:2.10.4-4.redhat_00004.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-jackson-modules-java8-0:2.10.4-2.redhat_00004.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-jettison-0:1.5.2-2.redhat_00002.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-netty-0:4.1.63-4.Final_redhat_00002.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-resteasy-0:3.11.6-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-snakeyaml-0:1.33.0-1.SP1_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2025:1747", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7", "package": "eap7-wildfly-0:7.3.12-3.GA_redhat_00002.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7", "release_date": "2025-02-24T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-artemis-wildfly-integration-0:1.0.4-1.redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-bouncycastle-0:1.68.0-2.redhat_00005.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-hal-console-0:3.2.14-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-infinispan-0:9.4.22-3.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-ironjacamar-0:1.4.30-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-jboss-genericjms-0:2.0.9-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-jboss-marshalling-0:2.0.11-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-jboss-server-migration-0:1.7.2-6.Final_redhat_00007.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-jboss-weld-3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-jgroups-kubernetes-0:1.0.16-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-mod_cluster-0:1.4.3-2.Final_redhat_00002.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-netty-0:4.1.60-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-resteasy-0:3.11.4-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-undertow-0:2.0.35-1.SP1_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-velocity-0:2.3.0-1.redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-weld-core-0:3.1.6-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-wildfly-0:7.3.7-1.GA_redhat_00002.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-wildfly-elytron-0:1.10.12-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-wildfly-http-client-0:1.0.26-1.Final_redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-xalan-j2-0:2.7.1-36.redhat_00013.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2046", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6", "impact": "moderate", "package": "eap7-yasson-0:1.0.9-1.redhat_00001.1.el6eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-artemis-wildfly-integration-0:1.0.4-1.redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-bouncycastle-0:1.68.0-2.redhat_00005.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-hal-console-0:3.2.14-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-infinispan-0:9.4.22-3.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-ironjacamar-0:1.4.30-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-jboss-genericjms-0:2.0.9-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-jboss-marshalling-0:2.0.11-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-jboss-server-migration-0:1.7.2-6.Final_redhat_00007.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-jboss-weld-3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-jgroups-kubernetes-0:1.0.16-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-mod_cluster-0:1.4.3-2.Final_redhat_00002.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-netty-0:4.1.60-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-resteasy-0:3.11.4-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-undertow-0:2.0.35-1.SP1_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-velocity-0:2.3.0-1.redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-weld-core-0:3.1.6-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-wildfly-0:7.3.7-1.GA_redhat_00002.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-wildfly-elytron-0:1.10.12-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-wildfly-http-client-0:1.0.26-1.Final_redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-xalan-j2-0:2.7.1-36.redhat_00013.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2047", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7", "impact": "moderate", "package": "eap7-yasson-0:1.0.9-1.redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-artemis-wildfly-integration-0:1.0.4-1.redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-bouncycastle-0:1.68.0-2.redhat_00005.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-hal-console-0:3.2.14-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-infinispan-0:9.4.22-3.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-ironjacamar-0:1.4.30-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-jboss-genericjms-0:2.0.9-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-jboss-marshalling-0:2.0.11-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-jboss-server-migration-0:1.7.2-6.Final_redhat_00007.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-jboss-weld-3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-jgroups-kubernetes-0:1.0.16-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-mod_cluster-0:1.4.3-2.Final_redhat_00002.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-netty-0:4.1.60-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-resteasy-0:3.11.4-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-undertow-0:2.0.35-1.SP1_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-velocity-0:2.3.0-1.redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-weld-core-0:3.1.6-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-wildfly-0:7.3.7-1.GA_redhat_00002.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-wildfly-elytron-0:1.10.12-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-wildfly-http-client-0:1.0.26-1.Final_redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-xalan-j2-0:2.7.1-36.redhat_00013.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:2048", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8", "impact": "moderate", "package": "eap7-yasson-0:1.0.9-1.redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8", "release_date": "2021-05-19T00:00:00Z"}, {"advisory": "RHSA-2021:3658", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8", "impact": "moderate", "package": "eap7-velocity-0:2.3.0-1.redhat_00001.1.el8eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "release_date": "2021-09-23T00:00:00Z"}, {"advisory": "RHSA-2021:3656", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7", "impact": "moderate", "package": "eap7-velocity-0:2.3.0-1.redhat_00001.1.el7eap", "product_name": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "release_date": "2021-09-23T00:00:00Z"}], "bugzilla": {"description": "velocity: arbitrary code execution when attacker is able to modify templates", "id": "1937440", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1937440"}, "csaw": false, "cvss3": {"cvss3_base_score": "8.8", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "(CWE-77|CWE-94)", "details": ["An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.", "A flaw was found in velocity. An attacker, able to modify Velocity templates, may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability."], "name": "CVE-2020-13936", "package_state": [{"cpe": "cpe:/a:redhat:a_mq_clients:2", "fix_state": "Not affected", "package_name": "velocity", "product_name": "A-MQ Clients 2"}, {"cpe": "cpe:/a:redhat:amq_broker:7", "fix_state": "Not affected", "impact": "low", "package_name": "velocity", "product_name": "Red Hat AMQ Broker 7"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:6", "fix_state": "Out of support scope", "package_name": "velocity", "product_name": "Red Hat BPM Suite 6"}, {"cpe": "cpe:/a:redhat:jboss_developer_studio:12.", "fix_state": "Affected", "package_name": "velocity", "product_name": "Red Hat CodeReady Studio 12"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:7", "fix_state": "Affected", "impact": "moderate", "package_name": "velocity", "product_name": "Red Hat Decision Manager 7"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Not affected", "package_name": "velocity", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:7", "fix_state": "Out of support scope", "impact": "moderate", "package_name": "velocity", "product_name": "Red Hat Enterprise Linux 7"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Fix deferred", "impact": "low", "package_name": "pki-deps:10.6/velocity", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/a:redhat:jboss_amq:6", "fix_state": "Out of support scope", "impact": "low", "package_name": "velocity", "product_name": "Red Hat JBoss A-MQ 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:6", "fix_state": "Out of support scope", "package_name": "velocity", "product_name": "Red Hat JBoss BRMS 6"}, {"cpe": "cpe:/a:redhat:jboss_data_virtualization:6", "fix_state": "Out of support scope", "package_name": "velocity", "product_name": "Red Hat JBoss Data Virtualization 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6", "fix_state": "Out of support scope", "package_name": "velocity", "product_name": "Red Hat JBoss Enterprise Application Platform 6"}, {"cpe": "cpe:/a:redhat:jboss_fuse:6", "fix_state": "Out of support scope", "impact": "moderate", "package_name": "velocity", "product_name": "Red Hat JBoss Fuse 6"}, {"cpe": "cpe:/a:redhat:jboss_fuse_service_works:6", "fix_state": "Out of support scope", "package_name": "velocity", "product_name": "Red Hat JBoss Fuse Service Works 6"}, {"cpe": "cpe:/a:redhat:jboss_operations_network:3", "fix_state": "Out of support scope", "package_name": "velocity", "product_name": "Red Hat JBoss Operations Network 3"}, {"cpe": "cpe:/a:redhat:openshift:3.11", "fix_state": "Will not fix", "impact": "moderate", "package_name": "openshift3/ose-logging-elasticsearch5", "product_name": "Red Hat OpenShift Container Platform 3.11"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Will not fix", "impact": "moderate", "package_name": "openshift4/ose-logging-elasticsearch5", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Will not fix", "impact": "moderate", "package_name": "openshift4/ose-logging-elasticsearch6", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Will not fix", "impact": "moderate", "package_name": "openshift4/ose-metering-hive", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7", "fix_state": "Affected", "impact": "moderate", "package_name": "velocity", "product_name": "Red Hat Process Automation 7"}], "public_date": "2021-03-09T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2020-13936\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-13936"], "statement": "OpenShift Container Platform (OCP) openshift-logging/elasticsearch6-rhel8 container does contain a vulnerable version of velocity. The references to the library only occur in the x-pack component which is an enterprise-only feature of Elasticsearch - hence it has been marked as wontfix as this time and may be fixed in a future release. Additionally the hive container only references velocity in the testutils of the code but the code still exists in the container, as such it has been given a Moderate impact.\n* Velocity as shipped with Red Hat Enterprise Linux 6 is not affected because it does not contain the vulnerable code.\n* Velocity as shipped with Red Hat Enterprise Linux 7 contains a vulnerable version, but it is used as a dependency for IdM/ipa, which does not use the vulnerable functionality. It has been marked as Moderate for this reason.\n* Although velocity shipped in Red Hat Enterprise Linux 8's pki-deps:10.6 for IdM/ipa is a vulnerable version, the vulnerable code is not used by pki. It has been marked as Low for this reason.", "threat_severity": "Important"}