Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update to the images for Red Hat Integration - Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Service Registry (container images) release and security update [2.4.3 GA] Advisory ID: RHSA-2023:3815-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:3815 Issue date: 2023-06-27 CVE Names: CVE-2021-46877 CVE-2022-3509 CVE-2022-3510 CVE-2022-3782 CVE-2022-4742 CVE-2022-25881 CVE-2022-40152 CVE-2022-45787 CVE-2023-28867 ==================================================================== 1. Summary: An update to the images for Red Hat Integration - Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This release of Red Hat Integration - Service Registry 2.4.3 GA includes the following security fixes. Security Fix(es): * keycloak: path traversal via double URL encoding (CVE-2022-3782) * jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode (CVE-2021-46877) * protobuf-java: Textformat parsing issue leads to DoS (CVE-2022-3509) * protobuf-java: Message-Type Extensions parsing issue leads to DoS (CVE-2022-3510) * json-pointer: prototype pollution in json-pointer (CVE-2022-4742) *http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability (CVE-2022-25881) * woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks (CVE-2022-40152) * apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider (CVE-2022-45787) * graphql-java: crafted GraphQL query causes stack consumption (CVE-2023-28867) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2134291 - CVE-2022-40152 woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks 2138971 - CVE-2022-3782 keycloak: path traversal via double URL encoding 2156333 - CVE-2022-4742 json-pointer: prototype pollution in json-pointer 2158916 - CVE-2022-45787 apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider 2165824 - CVE-2022-25881 http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability 2181977 - CVE-2023-28867 graphql-java: crafted GraphQL query causes stack consumption 2184161 - CVE-2022-3509 protobuf-java: Textformat parsing issue leads to DoS 2184176 - CVE-2022-3510 protobuf-java: Message-Type Extensions parsing issue leads to DoS 2185707 - CVE-2021-46877 jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode 5.References: https://access.redhat.com/security/cve/CVE-2021-46877 https://access.redhat.com/security/cve/CVE-2022-3509 https://access.redhat.com/security/cve/CVE-2022-3510 https://access.redhat.com/security/cve/CVE-2022-3782 https://access.redhat.com/security/cve/CVE-2022-4742 https://access.redhat.com/security/cve/CVE-2022-25881 https://access.redhat.com/security/cve/CVE-2022-40152 https://access.redhat.com/security/cve/CVE-2022-45787 https://access.redhat.com/security/cve/CVE-2023-28867 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZJsFgtzjgjWX9erEAQhjSxAAkdZcVQ40k/RGIbaO43BZYsPXzr3F47f9 kR7ddrW/LgLw6N2oHPx+T7zSMJM6oGnWjTi1Mqw6XUmDaSXSnLf2ADx3NEmrH//T 8Ti9UjN6oKuBtJb5sejU9ra2FBX9g3rJP6nb6QeeUi6v/a1aw3kwMp/mCC7Sp1U3 RxLOs9O4/CKA5NBSJnPjFqp1rXPLpmHLwOKdomABrOEoyIairtCey3GpLfOcLRMg +rNwtcjGrfMVQTC0d+2Gl4oNL7oqG6/fG/hRUFSO8LRzq+pEzEPA7bqgYi9wbbiX hEooNDJfAoUSbRljoYwqSpAROuyPft32+PhemRkX8/OUij213ouA9BFY14pf3X1y 5bmJI59ipH67tl8gO1naNlHDTbyZBr2wWxmjGadVOR9aJK5YDyosoUEk/gjokQbn 31sBfBHx2P9xCHTLZjDDNQBF9MgI1zh6dUId7pBNvcshcLLM5+7kbMGEf6l+elfm D89TciTpHROFfNLP6ejNzw/iE7Mm3pSb1UfEwamyvl/KSpoO39aMzxmRAy35ZV2A CrVPnrzEj2rCH3MvJTCc8CVz0p58zxrbBKJ6lLEecaEbAIvHeuKBmsWjDzf2DoLm ixoYo2VaKXPTYFpKon6HqR9ln4lL+VCMNiDyHk3AulBtkcgFzpMlfzeaHGlx9dRl IzcckdicBSE=lmeY -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update to the images for Red Hat Integration Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Service Registry (container images) release and security update [2.3.0.GA] Advisory ID: RHSA-2022:6835-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2022:6835 Issue date: 2022-10-06 CVE Names: CVE-2021-22569 CVE-2021-37136 CVE-2021-37137 CVE-2021-41269 CVE-2022-0235 CVE-2022-0536 CVE-2022-0981 CVE-2022-21724 CVE-2022-23647 CVE-2022-24771 CVE-2022-24772 CVE-2022-24773 CVE-2022-25647 CVE-2022-25857 CVE-2022-25858 CVE-2022-26520 CVE-2022-31129 CVE-2022-37734 ==================================================================== 1. Summary: An update to the images for Red Hat Integration Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This release of Red Hat Integration - Service registry 2.3.0.GA serves as a replacement for 2.0.3.GA, and includes the below security fixes. Security Fix(es): * cron-utils: template Injection leading to unauthenticated Remote Code Execution (CVE-2021-41269) * prismjs: improperly escaped output allows a XSS(CVE-2022-23647) * snakeyaml: Denial of Service due missing to nested depth limitation for collections (CVE-2022-25857) * moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129) * moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129) * protobuf-java: potential DoS in the parsing procedure for binary data (CVE-2021-22569) * quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus (CVE-2022-0981) * quarkus-jdbc-postgresql-deployment: jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes (CVE-2022-21724) * netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way (CVE-2021-37137) * netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data (CVE-2021-37136) * node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235) * follow-redirects: Exposure of Sensitive Information via Authorization Header leak (CVE-2022-0536) * jdbc-postgresql: postgresql-jdbc: Arbitrary File Write Vulnerability (CVE-2022-26520) * node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery (CVE-2022-24771) * node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery (CVE-2022-24772) * node-forge: Signature verification leniency in checking `DigestInfo` structure (CVE-2022-24773) * com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson (CVE-2022-25647) * terser: insecure use of regular expressions leads to ReDoS (CVE-2022-25858) * graphql-java: DoS by malicious query (CVE-2022-37734) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have beenapplied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2004133 - CVE-2021-37136 netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data 2004135 - CVE-2021-37137 netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way 2024632 - CVE-2021-41269 cron-utils: template Injection leading to unauthenticated Remote Code Execution 2039903 - CVE-2021-22569 protobuf-java: potential DoS in the parsing procedure for binary data 2044591 - CVE-2022-0235 node-fetch: exposure of sensitive information to an unauthorized actor 2050863 - CVE-2022-21724 jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes 2053259 - CVE-2022-0536 follow-redirects: Exposure of Sensitive Information via Authorization Header leak 2056643 - CVE-2022-23647 prismjs: improperly escaped output allows a XSS 2062520 - CVE-2022-0981 quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus 2064007 - CVE-2022-26520 postgresql-jdbc: Arbitrary File Write Vulnerability 2067387 - CVE-2022-24771 node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery 2067458 - CVE-2022-24772 node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery 2067461 - CVE-2022-24773 node-forge: Signature verification leniency in checking `DigestInfo` structure 2080850 - CVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson 2105075 - CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS 2126277 - CVE-2022-25858 terser: insecure use of regular expressions leads to ReDoS 2126789 - CVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collections 2126809 - CVE-2022-37734 graphql-java: DoS by malicious query 5.References: https://access.redhat.com/security/cve/CVE-2021-22569 https://access.redhat.com/security/cve/CVE-2021-37136 https://access.redhat.com/security/cve/CVE-2021-37137 https://access.redhat.com/security/cve/CVE-2021-41269 https://access.redhat.com/security/cve/CVE-2022-0235 https://access.redhat.com/security/cve/CVE-2022-0536 https://access.redhat.com/security/cve/CVE-2022-0981 https://access.redhat.com/security/cve/CVE-2022-21724 https://access.redhat.com/security/cve/CVE-2022-23647 https://access.redhat.com/security/cve/CVE-2022-24771 https://access.redhat.com/security/cve/CVE-2022-24772 https://access.redhat.com/security/cve/CVE-2022-24773 https://access.redhat.com/security/cve/CVE-2022-25647 https://access.redhat.com/security/cve/CVE-2022-25857 https://access.redhat.com/security/cve/CVE-2022-25858 https://access.redhat.com/security/cve/CVE-2022-26520 https://access.redhat.com/security/cve/CVE-2022-31129 https://access.redhat.com/security/cve/CVE-2022-37734 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYz7stNzjgjWX9erEAQiCEQ/+OPmlKRufUR1D+rRvhWHeBMxdJ9NMoaMm rV3uH/FIiBLFSYWXgTY8gb53BVsZHEPfZ6G3ol70iyOjDbXazQsYBuhg/9RMLmz9 +J1yK5sSeE9HyisYbYdHuuGIKpEMGXp78NP1rlwBEgyFrkY8pJHSdv/Fc87f2B3Z VeExd/Zvdcj5M4/ZmCin1yNALPKlhnbp9+9MGvcLufJUsXxOKPrQVCYMgWVWc0Wc aNRm4y8FBOnYrB9FeA2BBYEpmBrRK8G8OsoebuqaBvKAvytVV/NSiOMKsdaGD9WL XeLPl5XE3rpEVeUEH4aEjdHe6weLk/sjst335xgWI7QHZT/gjZxmxza2TBGgIkRJ yBT/n63geWAkaTXUCP0oepJDPKAio6B/CFVzTZS8jqO/0rDDvHIZN94nhceqamW3 GC5gha56Pk+qcw3sArvtu0G72wY5O/+/kxp0mV+sWczIIlbS7FlkG+sxl5uHo3+M DDBOMwNROI6bInBxnBD4GWMepW40cGaAXt1HN/1NVaZq0mw4cdyulOMJfPpJGQK5 IGS+TnvZn86p3cZysR3eMuaPzFG9U8vnaAw8enRmiJ6wG3NFkklIRelO7fEF8n3R drGnqa8gB589c9x3QUurBytdDxYWd2T71TOTyMFdTI9NtOAeuIvX+6lDj0BOftH3 Jnw+PamuYNc=ccnF -----END PGP SIGNATURE----- -- RHSA-announce mailinglist
An update to the images for Red Hat Integration Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Integration - Service Registry release and security update [2.0.3.GA] Advisory ID: RHSA-2022:0501-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2022:0501 Issue date: 2022-02-09 CVE Names: CVE-2021-38153 CVE-2021-40690 ==================================================================== 1. Summary: An update to the images for Red Hat Integration Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This release of Red Hat Integration - Service registry 2.0.3.GA serves as a replacement for 2.0.2.GA, and includes the below security fixes. Security Fix(es): * kafka-clients: Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients (CVE-2021-38153) * xmlsec: xml-security: XPath Transform abuse allows for information disclosure (CVE-2021-40690) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your systemhave been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2009041 - CVE-2021-38153 Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients 2011190 - CVE-2021-40690 xml-security: XPath Transform abuse allows for information disclosure 5. References: https://access.redhat.com/security/cve/CVE-2021-38153 https://access.redhat.com/security/cve/CVE-2021-40690 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYgQ8q9zjgjWX9erEAQgxQw//Wik2A6cu2hHZb6pkf8ISuheV5OhVryFz RZFEmtJprcefdGPJXft8CHzLUyUk3VzBXFi4IE9vE2fZRRxq3Oxqj4iwkVguYxeM /BkGez8c2EiiPZeknpGEwUOtbLZmoZmMnuakwqAi/+bzrKAbb1dyLrKbaHG/iBXU w0rft2yKxau+DBHOrQJ7FbgetZbTbVVXaxwJsu9YepTrTuF+3WgFTMsu7AGbnS9S 6gM6Fp0sHWdYMrKVLsi/TTSh6zwzTvahbL8CGff7JbKhPLAmL1vi91LYvIxmQg53 A2XamGyup67WDXsyt7L/yEDTvqfuqAuVi2w2JuOsqdVewM5zjCeRpODZNc5Lrj4j yyoC42GFxZlEsjKSs+xVHxcDplRLfHcPV6lSMgv/nEb5xaCOVPgumtwGspie7hn7 u7dGV3vC/5Us1/c+ZhHuTlV9HVKsC/rN1TgWLXceKNQNoeTFyNLcm+rcrwnCBj4t qn6dCAwvfk5H/dcMi+8g/dJlrW0RK0qYI6ssavafsPosudljILj+AWlUU0xgtvei ad7Qdd+ZsUZLcIucD8yxTXU6l+wCboT/dJ014FAM1P73kXEyw35MqMt/N+fi+qwo QUSDuEU4DMOnnnacraoWkt9LplaFBHlbMQLadX1AQgZs6peg9gDn0m+RbcusAuJL AiSE+XJlFHA=2vnB -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update to the images for Red Hat Integration Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Integration - Service Registry release and security update [2.0.2.GA] Advisory ID: RHSA-2021:4100-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2021:4100 Issue date: 2021-11-02 Keywords: service-registry CVE Names: CVE-2020-13956 CVE-2021-20289 CVE-2021-20293 ==================================================================== 1. Summary: An update to the images for Red Hat Integration Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This release of Red Hat Integration - Service registry 2.0.2.GA serves as a replacement for 2.0.1.GA, and includes the below security fixes. Security Fix(es): * apache-httpclient: incorrect handling of malformed authority component in request URIs (CVE-2020-13956) * RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack (CVE-2021-20293) * resteasy: Error message exposes endpoint class information (CVE-2021-20289) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the Referencessection. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 1886587 - CVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIs 1935927 - CVE-2021-20289 resteasy: Error message exposes endpoint class information 1942819 - CVE-2021-20293 RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack 5. References: https://access.redhat.com/security/cve/CVE-2020-13956 https://access.redhat.com/security/cve/CVE-2021-20289 https://access.redhat.com/security/cve/CVE-2021-20293 https://access.redhat.com/security/updates/classification#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYYEyVtzjgjWX9erEAQinrA//WUo0zL0uDp5i0UDqGiqleOUd74mlJvsC UTzcXp179a9PDtMU0HD7SpPQMOHue+x8VYxpL4ETe5wxLshXjQ92WRiRViIJEVYO tBMVPNU7ytMhFrzjNJfyQHl+hbxwaVHTFWEB74SeCiHDK8LxyKNkFucG9l0lCbCR D6ZmKptHG/ROdZ6mBSTI3un9Y8ZJVSDSyUilZJtOORndDswbzdk/ArAhOLtEDZoo KPpOM0Xfw8YIanpJZ0sA4mputxh52+cJ2J17LMr4iiPW5bEOntplGlmsXTdJgyUg gaj/xDPGFwa+ugIjT0xG+l0vsGWTFHILvHhtQgGJ737FJNY2xsFxzNIyOI0DU6Ez HTHw6/QOFYj5svQz1CwQZLS7EoiytYpUuJz9iLM8SbUASnW2pO4/N1FTzfePle5H nxRDT1QdNr4rwRudqxF2zKyBl9nMTyJydEM7qbhP3ZoD7+ks0M1USdLSCjuQni7I j2y7ri9dimADgRRXAMdooAZFKcvQaHthyo5cbT5bS+vQyadxOFtEjkxn16j4+Fp5 AOl26kcUxfv6mERzm2r9j+T891YYqvW+TSRoFJ9fVUTsFjcBctyha1gpcm5+BuIt 8nUFFziKqXHXlTbtoyOgI4R11QjL+qV1U6gKQtqPQuCvVOcfW11g1eSNUhKvgNWk HFWIwhJW/3o=I1Oq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update to the images for Red Hat Integration Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Service Registry (container images) release and security update [1.1.1.GA] Advisory ID: RHSA-2021:2039-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2021:2039 Issue date: 2021-05-19 Keywords: service-registry CVE Names: CVE-2020-14040 CVE-2020-25638 CVE-2020-25649 ==================================================================== 1. Summary: An update to the images for Red Hat Integration Service Registry is now available from the Red Hat Container Catalog. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This release of Red Hat Integration - Service registry 1.1.1.GA serves as a replacement for 1.1.0.GA, and includes the below security fixes. Security Fix(es): * hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used (CVE-2020-25638) * jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) (CVE-2020-25649) * golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040) For more details about the security issue(s), including the impact,a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 1853652 - CVE-2020-14040 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash 1881353 - CVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used 1887664 - CVE-2020-25649 jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) 5. References: https://access.redhat.com/security/cve/CVE-2020-14040 https://access.redhat.com/security/cve/CVE-2020-25638 https://access.redhat.com/security/cve/CVE-2020-25649 https://access.redhat.com/security/updates/classification/#moderate https://catalog.redhat.com/en/software/container-stacks/detail/5ef2818e7dc79430ca5f4fd2 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYKTGCtzjgjWX9erEAQhLJQ//ZPdV9qQgM3ZomoLBvRSivyr5wKg6R3u9 O9lLqS3fNtC3J9ZS2SvyNKcHM98SNx9b8UXsRsqEgXjHL3eWphTLsFecrsdHsF8z exMiVPyacUhqf8KZgryKsOerrfO7rkNuM7w1UewTWSfC3Tzw29+J3t9Z0Hprjs5Z MdsInSRXVz6v+aRAWhriSSZak6TnpeDwXmz0twvknUpuCVHj9tqkc1dEO1D+itSD 1frJp8cafio7r9WfOJWj1vdypiUmvjESZJh4UR8zhEs8AHeoG+x+65VhFVaFhLQG uiWzyUBENazgz5GMFk5O0VReJs0eftcg6TkVHKbOk7p2mN8C2gLnP/WtlPuDGWZX IBKLuFGPZdAVdqJb6VMtk7uSIQ6PjY5YI0YOW14Gh/KZEGaVwxFJSnW70XTWqXPg aN5MHCaEcWRLV1aQs72A4ZGbCxSAlAVnnxpns0P6W2wzDbSGleZq4BGu+9L0MYtd QdeoGqMh3a3KnNzWxdk5/PuADLYB98DheFTJtxCH6XU5vE38gp80JiKRZtBaD6PE oY1eRJiHdmiz74QDCJUbUN4ToFXUSyixTjhHPrATpXdIrXmFUBB6E8c7CnEBfUr5 r9UIp8BME12owmnXAHdbtcUEGLpvs1wV5Our1g5nYvkteVM+eY5qdglRNqrTT2b2 u9LVCW4VSz0=7mPt -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.