First published: Tue Jun 18 2019(Updated: )
The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by Red Hat Certificate System.<br>Security Fix(es):<br><li> tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)</li> <li> tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)</li> <li> tomcat: Open redirect in default servlet (CVE-2018-11784)</li> <li> tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/apache-commons-collections | <3.2.2-10.module+el8.0.0+3248+9d514f3b | 3.2.2-10.module+el8.0.0+3248+9d514f3b |
redhat/apache-commons-lang | <2.6-21.module+el8.0.0+3248+9d514f3b | 2.6-21.module+el8.0.0+3248+9d514f3b |
redhat/bea-stax | <1.2.0-16.module+el8.0.0+3248+9d514f3b | 1.2.0-16.module+el8.0.0+3248+9d514f3b |
redhat/glassfish-fastinfoset | <1.2.13-9.module+el8.0.0+3248+9d514f3b | 1.2.13-9.module+el8.0.0+3248+9d514f3b |
redhat/glassfish-jaxb | <2.2.11-11.module+el8.0.0+3248+9d514f3b | 2.2.11-11.module+el8.0.0+3248+9d514f3b |
redhat/glassfish-jaxb-api | <2.2.12-8.module+el8.0.0+3248+9d514f3b | 2.2.12-8.module+el8.0.0+3248+9d514f3b |
redhat/jackson-annotations | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-core | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-databind | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-jaxrs-providers | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-module-jaxb-annotations | <2.7.6-4.module+el8.0.0+3248+9d514f3b | 2.7.6-4.module+el8.0.0+3248+9d514f3b |
redhat/jakarta-commons-httpclient | <3.1-28.module+el8.0.0+3248+9d514f3b | 3.1-28.module+el8.0.0+3248+9d514f3b |
redhat/javassist | <3.18.1-8.module+el8.0.0+3248+9d514f3b | 3.18.1-8.module+el8.0.0+3248+9d514f3b |
redhat/pki-servlet-container | <9.0.7-14.module+el8.0.0+3248+9d514f3b | 9.0.7-14.module+el8.0.0+3248+9d514f3b |
redhat/python-nss | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/resteasy | <3.0.26-3.module+el8.0.0+3248+9d514f3b | 3.0.26-3.module+el8.0.0+3248+9d514f3b |
redhat/slf4j | <1.7.25-4.module+el8.0.0+3248+9d514f3b | 1.7.25-4.module+el8.0.0+3248+9d514f3b |
redhat/stax-ex | <1.7.7-8.module+el8.0.0+3248+9d514f3b | 1.7.7-8.module+el8.0.0+3248+9d514f3b |
redhat/velocity | <1.7-24.module+el8.0.0+3248+9d514f3b | 1.7-24.module+el8.0.0+3248+9d514f3b |
redhat/xalan-j2 | <2.7.1-38.module+el8.0.0+3248+9d514f3b | 2.7.1-38.module+el8.0.0+3248+9d514f3b |
redhat/xerces-j2 | <2.11.0-34.module+el8.0.0+3248+9d514f3b | 2.11.0-34.module+el8.0.0+3248+9d514f3b |
redhat/xml-commons-apis | <1.4.01-25.module+el8.0.0+3248+9d514f3b | 1.4.01-25.module+el8.0.0+3248+9d514f3b |
redhat/xml-commons-resolver | <1.2-26.module+el8.0.0+3248+9d514f3b | 1.2-26.module+el8.0.0+3248+9d514f3b |
redhat/xmlstreambuffer | <1.5.4-8.module+el8.0.0+3248+9d514f3b | 1.5.4-8.module+el8.0.0+3248+9d514f3b |
redhat/xsom | <0-19.20110809svn.module+el8.0.0+3248+9d514f3b | 0-19.20110809svn.module+el8.0.0+3248+9d514f3b |
redhat/apache-commons-collections | <3.2.2-10.module+el8.0.0+3248+9d514f3b | 3.2.2-10.module+el8.0.0+3248+9d514f3b |
redhat/apache-commons-lang | <2.6-21.module+el8.0.0+3248+9d514f3b | 2.6-21.module+el8.0.0+3248+9d514f3b |
redhat/bea-stax-api | <1.2.0-16.module+el8.0.0+3248+9d514f3b | 1.2.0-16.module+el8.0.0+3248+9d514f3b |
redhat/glassfish-fastinfoset | <1.2.13-9.module+el8.0.0+3248+9d514f3b | 1.2.13-9.module+el8.0.0+3248+9d514f3b |
redhat/glassfish-jaxb-api | <2.2.12-8.module+el8.0.0+3248+9d514f3b | 2.2.12-8.module+el8.0.0+3248+9d514f3b |
redhat/glassfish-jaxb-core | <2.2.11-11.module+el8.0.0+3248+9d514f3b | 2.2.11-11.module+el8.0.0+3248+9d514f3b |
redhat/glassfish-jaxb-runtime | <2.2.11-11.module+el8.0.0+3248+9d514f3b | 2.2.11-11.module+el8.0.0+3248+9d514f3b |
redhat/glassfish-jaxb-txw2 | <2.2.11-11.module+el8.0.0+3248+9d514f3b | 2.2.11-11.module+el8.0.0+3248+9d514f3b |
redhat/jackson-annotations | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-core | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-databind | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-jaxrs-json-provider | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-jaxrs-providers | <2.9.8-1.module+el8.0.0+3248+9d514f3b | 2.9.8-1.module+el8.0.0+3248+9d514f3b |
redhat/jackson-module-jaxb-annotations | <2.7.6-4.module+el8.0.0+3248+9d514f3b | 2.7.6-4.module+el8.0.0+3248+9d514f3b |
redhat/jakarta-commons-httpclient | <3.1-28.module+el8.0.0+3248+9d514f3b | 3.1-28.module+el8.0.0+3248+9d514f3b |
redhat/javassist | <3.18.1-8.module+el8.0.0+3248+9d514f3b | 3.18.1-8.module+el8.0.0+3248+9d514f3b |
redhat/javassist-javadoc | <3.18.1-8.module+el8.0.0+3248+9d514f3b | 3.18.1-8.module+el8.0.0+3248+9d514f3b |
redhat/pki-servlet | <4.0-api-9.0.7-14.module+el8.0.0+3248+9d514f3b | 4.0-api-9.0.7-14.module+el8.0.0+3248+9d514f3b |
redhat/pki-servlet-container | <9.0.7-14.module+el8.0.0+3248+9d514f3b | 9.0.7-14.module+el8.0.0+3248+9d514f3b |
redhat/resteasy | <3.0.26-3.module+el8.0.0+3248+9d514f3b | 3.0.26-3.module+el8.0.0+3248+9d514f3b |
redhat/slf4j | <1.7.25-4.module+el8.0.0+3248+9d514f3b | 1.7.25-4.module+el8.0.0+3248+9d514f3b |
redhat/slf4j-jdk14 | <1.7.25-4.module+el8.0.0+3248+9d514f3b | 1.7.25-4.module+el8.0.0+3248+9d514f3b |
redhat/stax-ex | <1.7.7-8.module+el8.0.0+3248+9d514f3b | 1.7.7-8.module+el8.0.0+3248+9d514f3b |
redhat/velocity | <1.7-24.module+el8.0.0+3248+9d514f3b | 1.7-24.module+el8.0.0+3248+9d514f3b |
redhat/xalan-j2 | <2.7.1-38.module+el8.0.0+3248+9d514f3b | 2.7.1-38.module+el8.0.0+3248+9d514f3b |
redhat/xerces-j2 | <2.11.0-34.module+el8.0.0+3248+9d514f3b | 2.11.0-34.module+el8.0.0+3248+9d514f3b |
redhat/xml-commons-apis | <1.4.01-25.module+el8.0.0+3248+9d514f3b | 1.4.01-25.module+el8.0.0+3248+9d514f3b |
redhat/xml-commons-resolver | <1.2-26.module+el8.0.0+3248+9d514f3b | 1.2-26.module+el8.0.0+3248+9d514f3b |
redhat/xmlstreambuffer | <1.5.4-8.module+el8.0.0+3248+9d514f3b | 1.5.4-8.module+el8.0.0+3248+9d514f3b |
redhat/xsom | <0-19.20110809svn.module+el8.0.0+3248+9d514f3b | 0-19.20110809svn.module+el8.0.0+3248+9d514f3b |
redhat/python-nss-debugsource | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python-nss-doc | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python3-nss | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python3-nss-debuginfo | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python-nss-debugsource | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python-nss-doc | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python3-nss | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python3-nss-debuginfo | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python-nss-debugsource | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python-nss-doc | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python3-nss | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python3-nss-debuginfo | <1.0.1-10.module+el8.0.0+3248+9d514f3b | 1.0.1-10.module+el8.0.0+3248+9d514f3b |
redhat/python-nss-debugsource | <1.0.1-10.module+el8.0.0+3248+9d514f3b.aa | 1.0.1-10.module+el8.0.0+3248+9d514f3b.aa |
redhat/python-nss-doc | <1.0.1-10.module+el8.0.0+3248+9d514f3b.aa | 1.0.1-10.module+el8.0.0+3248+9d514f3b.aa |
redhat/python3-nss | <1.0.1-10.module+el8.0.0+3248+9d514f3b.aa | 1.0.1-10.module+el8.0.0+3248+9d514f3b.aa |
redhat/python3-nss-debuginfo | <1.0.1-10.module+el8.0.0+3248+9d514f3b.aa | 1.0.1-10.module+el8.0.0+3248+9d514f3b.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.