RHSA-2019:2720: Important: pki-deps:10.6 security update
The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by Red Hat Certificate System.Security Fix(es): jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution (CVE-2019-12384) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/apache-commons-collectionsto a version that resolves this vulnerability.Fixed in 3.2.2-10.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/apache-commons-langto a version that resolves this vulnerability.Fixed in 2.6-21.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/bea-staxto a version that resolves this vulnerability.Fixed in 1.2.0-16.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/glassfish-fastinfosetto a version that resolves this vulnerability.Fixed in 1.2.13-9.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/glassfish-jaxbto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/glassfish-jaxb-apito a version that resolves this vulnerability.Fixed in 2.2.12-8.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/jackson-annotationsto a version that resolves this vulnerability.Fixed in 2.9.9-1.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/jackson-coreto a version that resolves this vulnerability.Fixed in 2.9.9-1.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.9.2-1.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/jackson-jaxrs-providersto a version that resolves this vulnerability.Fixed in 2.9.9-1.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/jackson-module-jaxb-annotationsto a version that resolves this vulnerability.Fixed in 2.7.6-4.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 3.1-28.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/javassistto a version that resolves this vulnerability.Fixed in 3.18.1-8.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/pki-servlet-containerto a version that resolves this vulnerability.Fixed in 9.0.7-14.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/python-nssto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/resteasyto a version that resolves this vulnerability.Fixed in 3.0.26-3.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/slf4jto a version that resolves this vulnerability.Fixed in 1.7.25-4.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/stax-exto a version that resolves this vulnerability.Fixed in 1.7.7-8.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/velocityto a version that resolves this vulnerability.Fixed in 1.7-24.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/xalan-j2to a version that resolves this vulnerability.Fixed in 2.7.1-38.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/xerces-j2to a version that resolves this vulnerability.Fixed in 2.11.0-34.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/xml-commons-apisto a version that resolves this vulnerability.Fixed in 1.4.01-25.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/xml-commons-resolverto a version that resolves this vulnerability.Fixed in 1.2-26.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/xmlstreambufferto a version that resolves this vulnerability.Fixed in 1.5.4-8.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/xsomto a version that resolves this vulnerability.Fixed in 0-19.20110809svn.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/bea-stax-apito a version that resolves this vulnerability.Fixed in 1.2.0-16.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/glassfish-jaxb-coreto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/glassfish-jaxb-runtimeto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/glassfish-jaxb-txw2to a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/jackson-jaxrs-json-providerto a version that resolves this vulnerability.Fixed in 2.9.9-1.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/javassist-javadocto a version that resolves this vulnerability.Fixed in 3.18.1-8.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/pki-servletto a version that resolves this vulnerability.Fixed in 4.0-api-9.0.7-14.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/slf4j-jdk14to a version that resolves this vulnerability.Fixed in 1.7.25-4.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/python-nss-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/python-nss-docto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/python3-nssto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/python3-nss-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0 - Upgrade
Upgrade
redhat/python-nss-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0.aa - Upgrade
Upgrade
redhat/python-nss-docto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0.aa - Upgrade
Upgrade
redhat/python3-nssto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0.aa - Upgrade
Upgrade
redhat/python3-nss-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.0.0+3892+c903d3f0.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2720?
The severity of RHSA-2019:2720 is classified as moderate.
How do I fix the vulnerability identified in RHSA-2019:2720?
To fix the vulnerability in RHSA-2019:2720, update the affected packages to the specified remedial versions provided by Red Hat.
Which packages are affected by RHSA-2019:2720?
The affected packages include apache-commons-collections, jackson-databind, and several others listed in the advisory.
What type of vulnerability is reported in RHSA-2019:2720?
RHSA-2019:2720 reports a vulnerability due to the failure to block the logback-core class from polymorphic deserialization.
Is there a risk associated with not addressing RHSA-2019:2720?
Yes, not addressing RHSA-2019:2720 may lead to potential security risks, including unauthenticated remote code execution.