First published: Tue Mar 15 2022(Updated: )
A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-jboss-xnio-base | <0:3.8.7-1.SP1_redhat_00001.1.el8ea | 0:3.8.7-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.8.7-1.SP1_redhat_00001.1.el7ea | 0:3.8.7-1.SP1_redhat_00001.1.el7ea |
redhat/rh-sso7-keycloak | <0:15.0.8-1.redhat_00001.1.el7 | 0:15.0.8-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:15.0.8-1.redhat_00001.1.el8 | 0:15.0.8-1.redhat_00001.1.el8 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el7 | 0:18.0.3-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el8 | 0:18.0.3-1.redhat_00001.1.el8 |
redhat/rh-sso7 | <0:1-5.el9 | 0:1-5.el9 |
redhat/rh-sso7-javapackages-tools | <0:6.0.0-7.el9 | 0:6.0.0-7.el9 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el9 | 0:18.0.3-1.redhat_00001.1.el9 |
Redhat Integration Camel K | ||
Redhat Integration Camel Quarkus | ||
Redhat Single Sign-on | =7.0 | |
Redhat Xnio | <3.8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-0084 is a vulnerability found in XNIO, specifically in the notifyReadClosed method.
The severity of CVE-2022-0084 is high with a CVSS score of 7.5.
CVE-2022-0084 affects the following software packages: eap7-jboss-xnio-base, rh-sso7-keycloak, rh-sso7, rh-sso7-javapackages-tools, Redhat Integration Camel K, Redhat Integration Camel Quarkus, Redhat Single Sign-on, and Redhat Xnio.
To fix CVE-2022-0084, update to the appropriate version of the affected software packages. Refer to the Red Hat Security Advisories for more information.
The Common Weakness Enumeration (CWE) for CVE-2022-0084 is CWE-770.