Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
98

Red Hat OpenStack 16.2: RHSA-2022-6517-01 Important Container Update

Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. 2. Description: Release osp-director-operator images. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Release of containers for OSP 16.2.z director operator tech preview Advisory ID: RHSA-2022:6517-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:6517 Issue date: 2022-09-14 CVE Names: CVE-2021-41103 CVE-2022-1292 CVE-2022-1586 CVE-2022-2068 CVE-2022-2097 CVE-2022-30631 ==================================================================== 1. Summary: Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. 2. Description: Release osp-director-operator images Security Fix(es): * CVE-2022-30631 golang: compress/gzip: stack exhaustion in Reader.Read [important] * CVE-2021-41103 golang: containerd: insufficiently restricted permissions on container root and plugin directories [medium] 3. Solution: OSP 16.2.z Release - OSP Director Operator Containers 4. Bugs fixed (https://bugzilla.redhat.com/): 2011007 - CVE-2021-41103 containerd: insufficiently restricted permissions on container root and plugin directories 2107342 - CVE-2022-30631 golang: compress/gzip: stack exhaustion in Reader.Read 5. References: https://access.redhat.com/security/cve/CVE-2021-41103 https://access.redhat.com/security/cve/CVE-2022-1292 https://access.redhat.com/security/cve/CVE-2022-1586 https://access.redhat.com/security/cve/CVE-2022-2068 https://access.redhat.com/security/cve/CVE-2022-2097 https://access.redhat.com/security/cve/CVE-2022-30631 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYyInxNzjgjWX9erEAQj8iA//ayZQRYHLjJL7czXpd1rCmi7GsmJgEIb3 UyOJlfr9B/saUH+y1o87j/b5xMtRLHWFV3yEKCy5HNaCNd/qCtr0YlBvxzV+Zk7i 3q4qA7CDc8JYmc6JIjDqX175u0z4o3KuBNJO+nmQG13h2cGSjRKm7O1ddZGdyCrO +fJtz1pGZ+Hwko+4Mkxlaail8AowqK5wTsFfkdaXkuAIjc7ImOox9PR2A+MylnxL +fg++DQgDTgMjotQW0TmbsOKEyXmFfQK6c6yjLe/WeJPTdejMrq4m7soFA2d3b1x BPN2B7IhT6BYJzTjJ5TZwcbzNJpItS53Et2ZIZT+WVhld39lKqp6fDwGG3crpGrk 9tdvbbNgn9LZHJvJzAgt8APjjBmzvbo/LUx2mI5/b3VRqDOruRGXp2unseEgCCHK fhNrgQHz8Ttlm2ZNOEtkFFEA2wJ7nL0sNnSkorIfDOJOPL9HO0WOn6eAfnle9jDa MGs3rG9MIZ1mw+9DfLf+EJW92KS3DM281BWsXofQic/dlZgbI2bpm43Z06aJaSGF sdVUS3/hknx/Itpd8tqsZq74qKkF/2t+aRYVzuDf7XqXuO6LDP2NO/AyhoNCe+fZ HdE33A1LEQAM7Z4DY/Pl1bzfjTiYn53ZW5i4cEjTS9EbPwnJMpcEkh1p/Gp51Uyt 2nnxgBoed8A=8PTk -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest version of Red Hat OpenStack Platform 16.2.z director operator containers has been launched, featuring crucial updates and bug resolutions.. Red Hat OpenStack, Container Security, OSP 16.2, Important Fix, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 14, 2022 Important Red Hat
98

Red Hat OpenStack 16.2: RHSA-2022-5673 Important Security Update

Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. 2. Description: Release osp-director-operator images. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Release of containers for OSP 16.2.z director operator tech preview Advisory ID: RHSA-2022:5673-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:5673 Issue date: 2022-07-20 CVE Names: CVE-2021-3634 CVE-2021-3737 CVE-2021-4189 CVE-2021-40528 CVE-2021-41103 CVE-2021-43565 CVE-2022-1271 CVE-2022-1621 CVE-2022-1629 CVE-2022-22576 CVE-2022-25313 CVE-2022-25314 CVE-2022-26945 CVE-2022-27774 CVE-2022-27776 CVE-2022-27782 CVE-2022-29824 CVE-2022-30321 CVE-2022-30322 CVE-2022-30323 ==================================================================== 1. Summary: Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. 2. Description: Release osp-director-operator images Security Fix(es): * go-getter: unsafe download (issue 1 of 3) [Important] (CVE-2022-30321) * go-getter: unsafe download (issue 2 of 3) [Important] (CVE-2022-30322) * go-getter: unsafe download (issue 3 of 3) [Important] (CVE-2022-30323) * go-getter: command injection vulnerability [Important] (CVE-2022-26945) * golang.org/x/crypto: empty plaintext packet causes panic [Moderate] (CVE-2021-43565) * containerd: insufficiently restricted permissions on container root and plugin directories [Moderate] (CVE-2021-41103) 3. Solution: OSP 16.2 Release - OSP Director Operator Containers tech preview 4. Bugs fixed (https://bugzilla.redhat.com/): 2011007 - CVE-2021-41103 containerd:insufficiently restricted permissions on container root and plugin directories 2030787 - CVE-2021-43565 golang.org/x/crypto: empty plaintext packet causes panic 2092918 - CVE-2022-30321 go-getter: unsafe download (issue 1 of 3) 2092923 - CVE-2022-30322 go-getter: unsafe download (issue 2 of 3) 2092925 - CVE-2022-30323 go-getter: unsafe download (issue 3 of 3) 2092928 - CVE-2022-26945 go-getter: command injection vulnerability 5. References: https://access.redhat.com/security/cve/CVE-2021-3634 https://access.redhat.com/security/cve/CVE-2021-3737 https://access.redhat.com/security/cve/CVE-2021-4189 https://access.redhat.com/security/cve/CVE-2021-40528 https://access.redhat.com/security/cve/CVE-2021-41103 https://access.redhat.com/security/cve/CVE-2021-43565 https://access.redhat.com/security/cve/CVE-2022-1271 https://access.redhat.com/security/cve/CVE-2022-1621 https://access.redhat.com/security/cve/CVE-2022-1629 https://access.redhat.com/security/cve/CVE-2022-22576 https://access.redhat.com/security/cve/CVE-2022-25313 https://access.redhat.com/security/cve/CVE-2022-25314 https://access.redhat.com/security/cve/CVE-2022-26945 https://access.redhat.com/security/cve/CVE-2022-27774 https://access.redhat.com/security/cve/CVE-2022-27776 https://access.redhat.com/security/cve/CVE-2022-27782 https://access.redhat.com/security/cve/CVE-2022-29824 https://access.redhat.com/security/cve/CVE-2022-30321 https://access.redhat.com/security/cve/CVE-2022-30322 https://access.redhat.com/security/cve/CVE-2022-30323 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/errata/RHSA-2022:4991 https://access.redhat.com/containers 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYtg1odzjgjWX9erEAQgLKhAAmNPdMhNGBxVdTDymf3EpM8xQcr25XWOR wfdum3Q4/Ji9/IQJ1NCv/5IsphsHgDaKlo9pY9BPzgeT4z90ga+5ldcXgqC9dk74 KVBUURmWxfbkg57E5dWHkMb9fxyRIpo0NiFlwLx5ynjIjO/WwWwFzz4YIiktDy1H AgGz1oZnX+hdZ+BpH2Ltx70cCyqvHgA+aOFXGHZNl8qQXQEjtCBN957XEo4c1hgp 6HBmK3GkcaL2Ml32/EM+2j4BLyz4hUK9Xfe171le0RcjkIND9BNzx2055dXov9uY eN52pn7pL8BvWU37b39wZx4EEyluYfnnlLaM9I+Y0t0NFhtA2H5Xk/hei1W3tzkP FdSR6gYIB1wwkBKu/qus4RqrtDEhYHOYXqIziEE+G0nF0ht1As7kLq7U05n7spOu 9mKht4iXLj17lzPHAXM5N9HF0/v3WuVNQf1DXOzb29BUF14fGFzXCWp/nIG+PpEt efmBklT4DAgLaibGwKyLZ7YOcfl/mQoQDCs3uPqpqeXf799cTtJFmC520ox/eaFx OFQ1ZNpDI/FKi1919hl2Ox5V7OxOZRIs/MPsLJ+HBtr9CmGMV2/rezeTEu+cD7Ts SFDt82MQeqSJuxjpa04odqcU6NZbccoF3c7sxn49Vvk6AAn6umXgJCR/Pnp9QPZT /jnfjsj7xYM=+5tE -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Canonical announces crucial patches for Kubernetes 1.23.x cluster management images. Stay vigilant for protection.. Red Hat OpenStack, security fixes, 16.2.z, container vulnerabilities, technology preview. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 20, 2022 Important Red Hat
98

Red Hat OpenStack 16.2: RHSA-2022-2183-01 Moderate Release Advisory

Red Hat OpenStack Platform 16.2 (Train) director Operator containers are available for technology preview. 2. Description: Release osp-director-operator images. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Release of containers for OSP 16.2.z director operator tech preview Advisory ID: RHSA-2022:2183-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:2183 Issue date: 2022-05-11 CVE Names: CVE-2018-25032 CVE-2019-11253 CVE-2019-19794 CVE-2020-15257 CVE-2021-29482 CVE-2021-32760 CVE-2022-1154 CVE-2022-1271 ==================================================================== 1. Summary: Red Hat OpenStack Platform 16.2 (Train) director Operator containers are available for technology preview. 2. Description: Release osp-director-operator images Security Fix(es): * golang: kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote (CVE-2019-11253) * golang: golang-github-miekg-dns: predictable TXID can lead to response forgeries (CVE-2019-19794) * golang: containerd: unrestricted access to abstract Unix domain socket can lead to privileges (CVE-2020-15257) * golang: ulikunitz/xz: Infinite loop in readUvarint allows for denial of service (CVE-2021-29482) * golang: containerd: pulling and extracting crafted container image may result in Unix file permission changes (CVE-2021-32760) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 3. Solution: OSP 16.2 Release - OSP Director Operator Containers tech preview 4. Bugs fixed (https://bugzilla.redhat.com/): 1757701 - CVE-2019-11253 kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service 1786761- CVE-2019-19794 golang-github-miekg-dns: predictable TXID can lead to response forgeries 1899487 - CVE-2020-15257 containerd: unrestricted access to abstract Unix domain socket can lead to privileges escalation 1954368 - CVE-2021-29482 ulikunitz/xz: Infinite loop in readUvarint allows for denial of service 1982681 - CVE-2021-32760 containerd: pulling and extracting crafted container image may result in Unix file permission changes 2079447 - Rebase tech preview on latest upstream v1.2.x branch 5. References: https://access.redhat.com/security/cve/CVE-2018-25032 https://access.redhat.com/security/cve/CVE-2019-11253 https://access.redhat.com/security/cve/CVE-2019-19794 https://access.redhat.com/security/cve/CVE-2020-15257 https://access.redhat.com/security/cve/CVE-2021-29482 https://access.redhat.com/security/cve/CVE-2021-32760 https://access.redhat.com/security/cve/CVE-2022-1154 https://access.redhat.com/security/cve/CVE-2022-1271 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYnvx49zjgjWX9erEAQifFg//TCQNGh/8hkZ1S3v71P6N+j3RHuuxNg3G 1vq4Per7WcfFjeyBw/LCFp+Ul8Qb7XgtAAY1L5FW4m6uUgrgqcd3RtGS1m5xbO9/ jyRo90kvUEfh1kIJXFVBf5OOI9r0BaYcxlmdAmL7nDZTTQJyjjSHKv0XN/4Ic7r7 +R6TtwDNy2RlcPY6pggctR6MuxxUqsgkVWcfHBABcdvMyF2XEmrPkC9tzQXx6BdP 8HpxlvD2J/MXthqAcKxqPEmszOV41JTwsi/SFdk+5aA5XLlFwrNHvCRyK0FANO0P sM1EdU1ZnUK/Jo0G2xmMG+aExLC1IPaAQ0yA0LvBoV0Wh0oh3pJDB+8BVjnCJk3o AwdcNb+FOUaI4ZHlJ0wMQki97HyBazTG3NMVCfvko8/LCgkBA8ROQRSxOOjxhG0J T5uO0QYi16wWUQMmBj9S2LW0IX/iTpI4POTlVXD6b9PUR3WQ4bki4s1D61Ub7Uny /QCRDMAxQSZ4xFhfX+d3Q3V35C9Kyg3Bhce5KdDGmp1mVZRh1NmG46IW/1/GWfpv JljVcvbWH/4+rRF3fN7h2jAULRRziCeLin+noj1hqPTR+5DnNbGammKZjU8RafcA 4WbJO5kCqE4mjSfzPgyd26CxzES5vtlIpjYlglGfNwcCOc/oXshtARjrusOHfb1r uegJW1UHUAo=ny/g -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat haslaunched OpenStack Platform 16.2.z, enhancing security measures to address vulnerabilities and strengthen cloud infrastructures, urging updates for improved security.. Red Hat OpenStack, operator containers, security advisory. . LinuxSecurity.com Team

Calendar 2 May 11, 2022 Red Hat
98

Red Hat OSP 16.2: RHSA-2022:0842-01 Important Security Advisory

Red Hat OpenStack Platform 16.2 (Train) director Operator containers are available for technology preview. 2. Description: Release osp-director-operator images. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Release of containers for OSP 16.2 director operator tech preview Advisory ID: RHSA-2022:0842-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:0842 Issue date: 2022-03-14 CVE Names: CVE-2019-5827 CVE-2019-13750 CVE-2019-13751 CVE-2019-17594 CVE-2019-17595 CVE-2019-18218 CVE-2019-19603 CVE-2019-20838 CVE-2020-12762 CVE-2020-13435 CVE-2020-14155 CVE-2020-16135 CVE-2020-24370 CVE-2021-3200 CVE-2021-3426 CVE-2021-3445 CVE-2021-3521 CVE-2021-3572 CVE-2021-3580 CVE-2021-3712 CVE-2021-3800 CVE-2021-3872 CVE-2021-3984 CVE-2021-4019 CVE-2021-4122 CVE-2021-4192 CVE-2021-4193 CVE-2021-20231 CVE-2021-20232 CVE-2021-22876 CVE-2021-22898 CVE-2021-22925 CVE-2021-27645 CVE-2021-28153 CVE-2021-33560 CVE-2021-33574 CVE-2021-35942 CVE-2021-36084 CVE-2021-36085 CVE-2021-36086 CVE-2021-36087 CVE-2021-42574 CVE-2021-44716 CVE-2022-24407 ==================================================================== 1. Summary: Red Hat OpenStack Platform 16.2 (Train) director Operator containers are available for technology preview. 2. Description: Release osp-director-operator images Security Fix(es): * golang: net/http: limit growth of header canonicalization cache (CVE-2021-44716) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE pagelisted in the References section. 3. Solution: OSP 16.2.z Release - OSP Director Operator Containers 4. Bugs fixed (https://bugzilla.redhat.com/): 2025995 - Rebase tech preview on latest upstream v1.2.x branch 2030801 - CVE-2021-44716 golang: net/http: limit growth of header canonicalization cache 2036784 - osp controller (fencing enabled) in downed state after system manual crash test 5.References: https://access.redhat.com/security/cve/CVE-2019-5827 https://access.redhat.com/security/cve/CVE-2019-13750 https://access.redhat.com/security/cve/CVE-2019-13751 https://access.redhat.com/security/cve/CVE-2019-17594 https://access.redhat.com/security/cve/CVE-2019-17595 https://access.redhat.com/security/cve/CVE-2019-18218 https://access.redhat.com/security/cve/CVE-2019-19603 https://access.redhat.com/security/cve/CVE-2019-20838 https://access.redhat.com/security/cve/CVE-2020-12762 https://access.redhat.com/security/cve/CVE-2020-13435 https://access.redhat.com/security/cve/CVE-2020-14155 https://access.redhat.com/security/cve/CVE-2020-16135 https://access.redhat.com/security/cve/CVE-2020-24370 https://access.redhat.com/security/cve/CVE-2021-3200 https://access.redhat.com/security/cve/CVE-2021-3426 https://access.redhat.com/security/cve/CVE-2021-3445 https://access.redhat.com/security/cve/CVE-2021-3521 https://access.redhat.com/security/cve/CVE-2021-3572 https://access.redhat.com/security/cve/CVE-2021-3580 https://access.redhat.com/security/cve/CVE-2021-3712 https://access.redhat.com/security/cve/CVE-2021-3800 https://access.redhat.com/security/cve/CVE-2021-3872 https://access.redhat.com/security/cve/CVE-2021-3984 https://access.redhat.com/security/cve/CVE-2021-4019 https://access.redhat.com/security/cve/CVE-2021-4122 https://access.redhat.com/security/cve/CVE-2021-4192 https://access.redhat.com/security/cve/CVE-2021-4193 https://access.redhat.com/security/cve/CVE-2021-20231 https://access.redhat.com/security/cve/CVE-2021-20232 https://access.redhat.com/security/cve/CVE-2021-22876 https://access.redhat.com/security/cve/CVE-2021-22898 https://access.redhat.com/security/cve/CVE-2021-22925 https://access.redhat.com/security/cve/CVE-2021-27645 https://access.redhat.com/security/cve/CVE-2021-28153 https://access.redhat.com/security/cve/CVE-2021-33560 https://access.redhat.com/security/cve/CVE-2021-33574 https://access.redhat.com/security/cve/CVE-2021-35942 https://access.redhat.com/security/cve/CVE-2021-36084 https://access.redhat.com/security/cve/CVE-2021-36085 https://access.redhat.com/security/cve/CVE-2021-36086 https://access.redhat.com/security/cve/CVE-2021-36087 https://access.redhat.com/security/cve/CVE-2021-42574 https://access.redhat.com/security/cve/CVE-2021-44716 https://access.redhat.com/security/cve/CVE-2022-24407 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYi+u+dzjgjWX9erEAQgHbg/+KnDnid8f3BWNfmZE77w/U9Gn7NimIkZu gdVWuaseK2pIncyilEzFN2C1egjoQscbI6BWSjZI6h0066NN+i6q3dTjS6/sb9nv G71Unez1L2xQOcMtlY4gwJzJm1FEquE6gAqsr1fsNYR7cqWKWhcxvMgkUuvr6pGL TPbYatG2kj409YTu83wQQlPOY7kRJiU24KuPeSH0Nigmddk5JXqcsIn3h6lM7nzR uva7ngXJD3Fn2+FZ8VB3bKYFCugnWccleaIZC2m9HMuoPVOZbFwgggmxk1tPaQJk jxAHjX+fK2WLhFh8BZT9m41aY6oa1kKeQo24r1jGOdZVNxBuA28JxOgLja/87HIG SK06H5RRAFjwJRjsnnoy4LPW5o0tzPj7/u2D1C/KDhY7iHvKT3RoU+Wj5yQ4pUCM bxQvX+k4y70VPlfxCFsu7DhMX9EquH3QTGaBjMcDYJSrijMqn8fRP7hS0QsndtpQ /p9ltfqoxcI7MJWgnA62qlzar8/dnZXj94bq/jZEehtQp71FTEdtA1AgDW4uIw0y zVd2mqKRBfaq8MCCGf+R1L/e4OAL0nwWrWLG4K6yU+d4+HZGGBolb4nxgVZbn1k/ 2ohCJb8ZePHayYsNz8hWwU3f5IvEgYu65gxmedr5F6KfKyU6DrIGkIr7YAkUkmHU khjXTHG9e5w=1SVS -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . The latest release of Red Hat OpenShift 4.10 unveils enhanced observability tools in tech preview, significantly improving application performance insights.. OpenStack, Red Hat, OSP, Containers, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 14, 2022 Important Red Hat
98

Red Hat Integration: RHSA-2021-0110-01 Important XML Security Issue

An update to the Camel K operator image for Red Hat Integration tech-preview is now available. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Tech-Preview 2 Camel K security update Advisory ID: RHSA-2021:0110-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2021:0110 Issue date: 2021-01-13 Keywords: fuse CVE Names: CVE-2020-13692 ==================================================================== 1. Summary: An update to the Camel K operator image for Red Hat Integration tech-preview is now available. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This release of Red Hat Integration - Camel K - Tech-Preview 2 serves as a replacement for tech-preview 1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, referto: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 1852985 - CVE-2020-13692 postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML 5. References: https://access.redhat.com/security/cve/CVE-2020-13692 https://access.redhat.com/security/updates/classification#important https://docs.redhat.com/en/documentation/red_hat_integration/2020-q4/html/release_notes_for_red_hat_integration_2020-q4/index 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX/81qtzjgjWX9erEAQi7FQ//VV6Cn5nZxjx9ER9g0VUes293jgDQAK23 bJMrArEkz7Ie5zBbVW4p2SlL8Fbg4GHxUbD8snq4F6CTyqrJ776E8OLVr02TM76C IysYjx+afLYOtw6kI3JeeKJpuYGskzRBJXlQKwf4upnk5FIeWNpX2IAvIxzRxn0c Z3VhEJcswSpYkVVJ36gdmKhato5Oet3/HsAHi6NkIEWj0wJyG2oUhppUydUjQEou 24LPrgg9g+8W3lH7Vq3Nhgid2I67OSdtnw/yWGWkfivn1gF2cg7jKVYO08O9d1yU 5twSInm37/cI1wnzfcyMYTv7qaU9u89X3THdUiM3tMOBKNqYwqoslrHYs7s2vZa1 lzYe22ZTcBcxWkut0bl4oKVBXysYxpMo6jcxUh0DNSh37YqbVYhwRlsaLayhqKr4 5O0m6qX4dIwBpfVe93juSaOcmaifr9V/bNiWVTQvX5X+KXCYYhhNXU2IdtvulWtD Hcfawx/o3c7PpPoCiBxoQcIeZw56PM5SOC3Os+5uIZc6yL9JGC6I+8Ih9OIIxQWE /HYxpy3uJfa07ii0C7Vv+r45i03r5L0FgcOPUYfx3IYdlbM04BMwvnjSf76yiied MvCmKb7/YoxU97RBeTJ+ujdYQ5qtAGpxsvJjqiJ5/oGSYQuiWo4PBkntlI3qjhuF eAsY6MXUDXQ=qb9B -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial patch released for Red Hat Integration Camel K tackling XML External Entity risk to enhance protection.. Red Hat Integration,Camel K,XML External Entity,Security Update,Tech Preview. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 13, 2021 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here