RHSA-2019:1529: Important: pki-deps:10.6 security update
The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by Red Hat Certificate System.Security Fix(es): tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037) tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014) tomcat: Open redirect in default servlet (CVE-2018-11784) tomcat: Host name verification missing in WebSocket client (CVE-2018-8034) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/apache-commons-collectionsto a version that resolves this vulnerability.Fixed in 3.2.2-10.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/apache-commons-langto a version that resolves this vulnerability.Fixed in 2.6-21.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/bea-staxto a version that resolves this vulnerability.Fixed in 1.2.0-16.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/glassfish-fastinfosetto a version that resolves this vulnerability.Fixed in 1.2.13-9.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/glassfish-jaxbto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/glassfish-jaxb-apito a version that resolves this vulnerability.Fixed in 2.2.12-8.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/jackson-annotationsto a version that resolves this vulnerability.Fixed in 2.9.8-1.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/jackson-coreto a version that resolves this vulnerability.Fixed in 2.9.8-1.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8-1.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/jackson-jaxrs-providersto a version that resolves this vulnerability.Fixed in 2.9.8-1.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/jackson-module-jaxb-annotationsto a version that resolves this vulnerability.Fixed in 2.7.6-4.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 3.1-28.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/javassistto a version that resolves this vulnerability.Fixed in 3.18.1-8.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/pki-servlet-containerto a version that resolves this vulnerability.Fixed in 9.0.7-14.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/python-nssto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/resteasyto a version that resolves this vulnerability.Fixed in 3.0.26-3.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/slf4jto a version that resolves this vulnerability.Fixed in 1.7.25-4.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/stax-exto a version that resolves this vulnerability.Fixed in 1.7.7-8.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/velocityto a version that resolves this vulnerability.Fixed in 1.7-24.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/xalan-j2to a version that resolves this vulnerability.Fixed in 2.7.1-38.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/xerces-j2to a version that resolves this vulnerability.Fixed in 2.11.0-34.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/xml-commons-apisto a version that resolves this vulnerability.Fixed in 1.4.01-25.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/xml-commons-resolverto a version that resolves this vulnerability.Fixed in 1.2-26.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/xmlstreambufferto a version that resolves this vulnerability.Fixed in 1.5.4-8.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/xsomto a version that resolves this vulnerability.Fixed in 0-19.20110809svn.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/bea-stax-apito a version that resolves this vulnerability.Fixed in 1.2.0-16.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/glassfish-jaxb-coreto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/glassfish-jaxb-runtimeto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/glassfish-jaxb-txw2to a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/jackson-jaxrs-json-providerto a version that resolves this vulnerability.Fixed in 2.9.8-1.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/javassist-javadocto a version that resolves this vulnerability.Fixed in 3.18.1-8.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/pki-servletto a version that resolves this vulnerability.Fixed in 4.0-api-9.0.7-14.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/slf4j-jdk14to a version that resolves this vulnerability.Fixed in 1.7.25-4.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/python-nss-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/python-nss-docto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/python3-nssto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/python3-nss-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b - Upgrade
Upgrade
redhat/python-nss-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b.aa - Upgrade
Upgrade
redhat/python-nss-docto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b.aa - Upgrade
Upgrade
redhat/python3-nssto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b.aa - Upgrade
Upgrade
redhat/python3-nss-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3248+9d514f3b.aa - Upgrade
Upgrade
tomcatto a version that resolves this vulnerability.Patch CVE-2018-8034 - Upgrade
Upgrade
tomcatto a version that resolves this vulnerability.Patch CVE-2018-8014 - Upgrade
Upgrade
tomcatto a version that resolves this vulnerability.Patch CVE-2018-11784 - Upgrade
Upgrade
pki-deps:10.6to a version that resolves this vulnerability.Patch CVE-2018-8037
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:1529?
The severity of RHSA-2019:1529 is high due to session handling vulnerabilities in the tomcat component.
How do I fix RHSA-2019:1529?
To fix RHSA-2019:1529, update the affected packages to their respective remedied versions as specified in the advisory.
What components are affected by RHSA-2019:1529?
RHSA-2019:1529 affects multiple components including tomcat and various libraries such as apache-commons, jackson, and glassfish.
What are the potential risks if RHSA-2019:1529 is not addressed?
If RHSA-2019:1529 is not addressed, user sessions could be compromised, leading to unauthorized access and information leakage.
Is RHSA-2019:1529 applicable to all Red Hat systems?
RHSA-2019:1529 specifically applies to Red Hat Enterprise Linux 8 systems that utilize the affected components.