First published: Fri Jun 10 2022(Updated: )
A flaw was found in pki-core. Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. A remote attacker could potentially use this flaw to retrieve the content of arbitrary files by sending specially crafted HTTP requests. Upstream PR: <a href="https://github.com/dogtagpki/pki/pull/4021">https://github.com/dogtagpki/pki/pull/4021</a> Upstream commit: <a href="https://github.com/dogtagpki/pki/commit/4e893243d72ad766558c10c907841f5f9c047055">https://github.com/dogtagpki/pki/commit/4e893243d72ad766558c10c907841f5f9c047055</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/pki-core | <0:10.5.18-24.el7 | 0:10.5.18-24.el7 |
redhat/pki-core | <0:10.5.18-24.el7_9 | 0:10.5.18-24.el7_9 |
redhat/pki-core | <0:11.0.6-2.el9_0 | 0:11.0.6-2.el9_0 |
Dogtagpki Dogtagpki | =10.5.18 | |
Dogtagpki Dogtagpki | =10.7.4 | |
Dogtagpki Dogtagpki | =10.8.3 | |
Dogtagpki Dogtagpki | =10.11.2 | |
Dogtagpki Dogtagpki | =10.12.4 | |
Dogtagpki Dogtagpki | =11.0.5 | |
Dogtagpki Dogtagpki | =11.1.0 | |
redhat/pki-core | <10.5.19 | 10.5.19 |
redhat/pki-core | <10.7.5 | 10.7.5 |
redhat/pki-core | <10.8.4 | 10.8.4 |
redhat/pki-core | <10.11.3 | 10.11.3 |
redhat/pki-core | <10.12.5 | 10.12.5 |
redhat/pki-core | <11.0.6 | 11.0.6 |
redhat/pki-core | <11.1.1 | 11.1.1 |
redhat/pki-core | <11.2.0 | 11.2.0 |
debian/dogtag-pki | <=10.10.2-3 | 11.2.1-2 |
There is no known mitigation for this issue, please update the affected package as soon as possible.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-2414 is a vulnerability that allows remote attackers to potentially retrieve the content of arbitrary files by exploiting XML external entity (XXE) attacks.
CVE-2022-2414 has a severity rating of 7.5 (high).
CVE-2022-2414 affects pki-core versions 10.5.19, 10.7.5, 10.8.4, 10.11.3, 10.12.5, 11.0.6, 11.1.1, and 11.2.0.
To fix CVE-2022-2414, update pki-core to version 10.5.19, 10.7.5, 10.8.4, 10.11.3, 10.12.5, 11.0.6, 11.1.1, or 11.2.0.
More information about CVE-2022-2414 can be found at the following references: [CVE-2022-2414](https://www.cve.org/CVERecord?id=CVE-2022-2414), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-2414), [RedHat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2104676), [RedHat Security Advisory](https://access.redhat.com/errata/RHSA-2022:8915).