RHSA-2022:7470-01 -- Redhat apache-commons-collections, apache-commons-lang, apache-commons-net, bea-stax-api, glassfish-fastinfoset, glassfish-jaxb, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, jackson-module-jaxb-annotations, jakarta-commons-httpclient, javassist, jss, ldapjdk, pki-core, python-nss, relaxngDatatype, resteasy, slf4j, stax-ex, tomcatjss, velocity, xalan-j2, xerces-j2, xml-commons-apis, xml-commons-resolver, xmlstreambuffer, xsom-0, idm-pki-symkey, idm-pki-tools, python3-nss, idm-pki-acme, idm-pki-base, idm-pki-ca, idm-pki-kra, idm-pki-server, jackson-jaxrs-json-provider, pki-servlet, python3-idm-pkiID: oval:org.secpod.oval:def:507274 | Date: (C)2023-02-06 (M)2023-02-06 | Class: PATCH | Family: unix |
The Public Key Infrastructure Core contains fundamental packages required by Red Hat Certificate System. Security Fix: * pki-core: access to external entities when parsing XML can lead to XXE For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section. Platform: | Red Hat Enterprise Linux 8 |
Product: | apache-commons-collections | apache-commons-lang | apache-commons-net | bea-stax-api | glassfish-fastinfoset | glassfish-jaxb-api | glassfish-jaxb-core | glassfish-jaxb-runtime | glassfish-jaxb-txw2 | jackson-annotations | jackson-core | jackson-databind | jackson-jaxrs-providers | jackson-module-jaxb-annotations | jakarta-commons-httpclient | javassist | jss | ldapjdk | python-nss-doc | relaxngDatatype | resteasy | slf4j | stax-ex | tomcatjss | velocity | xalan-j2 | xerces-j2 | xml-commons-apis | xml-commons-resolver | xmlstreambuffer | xsom | idm-pki-symkey | idm-pki-tools | python3-nss | idm-pki-acme | idm-pki-base | idm-pki-ca | idm-pki-kra | idm-pki-server | jackson-jaxrs-json-provider | pki-servlet-engine | python3-idm-pki |
|