RHSA-2020:1644: Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

Published Apr 28, 2020
·
Updated

The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.Security Fix(es): jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig (CVE-2019-14540) jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource (CVE-2019-16335) jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources. (CVE-2019-16942) jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource (CVE-2019-16943) jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db. (CVE-2019-17531) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.2 Release Notes linked from the References section.

Affected Software

123 affected componentsFixes available
redhat/apache-commons-collections<3.2.2-10.module+el8.1.0+3366+6dfb954c
3.2.2-10.module+el8.1.0+3366+6dfb954c
redhat/apache-commons-lang<2.6-21.module+el8.1.0+3366+6dfb954c
2.6-21.module+el8.1.0+3366+6dfb954c
redhat/bea-stax<1.2.0-16.module+el8.1.0+3366+6dfb954c
1.2.0-16.module+el8.1.0+3366+6dfb954c
redhat/glassfish-fastinfoset<1.2.13-9.module+el8.1.0+3366+6dfb954c
1.2.13-9.module+el8.1.0+3366+6dfb954c
redhat/glassfish-jaxb<2.2.11-11.module+el8.1.0+3366+6dfb954c
2.2.11-11.module+el8.1.0+3366+6dfb954c
redhat/glassfish-jaxb-api<2.2.12-8.module+el8.1.0+3366+6dfb954c
2.2.12-8.module+el8.1.0+3366+6dfb954c
redhat/jackson-annotations<2.10.0-1.module+el8.2.0+5059+3eb3af25
2.10.0-1.module+el8.2.0+5059+3eb3af25
redhat/jackson-core<2.10.0-1.module+el8.2.0+5059+3eb3af25
2.10.0-1.module+el8.2.0+5059+3eb3af25
redhat/jackson-databind<2.10.0-1.module+el8.2.0+5059+3eb3af25
2.10.0-1.module+el8.2.0+5059+3eb3af25
redhat/jackson-jaxrs-providers<2.9.9-1.module+el8.1.0+3832+9784644d
2.9.9-1.module+el8.1.0+3832+9784644d
redhat/jackson-module-jaxb-annotations<2.7.6-4.module+el8.1.0+3366+6dfb954c
2.7.6-4.module+el8.1.0+3366+6dfb954c
redhat/jakarta-commons-httpclient<3.1-28.module+el8.1.0+3366+6dfb954c
3.1-28.module+el8.1.0+3366+6dfb954c
redhat/javassist<3.18.1-8.module+el8.1.0+3366+6dfb954c
3.18.1-8.module+el8.1.0+3366+6dfb954c
redhat/pki-servlet-engine<9.0.7-16.module+el8.1.0+3366+6dfb954c
9.0.7-16.module+el8.1.0+3366+6dfb954c
redhat/python-nss<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/resteasy<3.0.26-3.module+el8.1.0+3366+6dfb954c
3.0.26-3.module+el8.1.0+3366+6dfb954c
redhat/slf4j<1.7.25-4.module+el8.1.0+3366+6dfb954c
1.7.25-4.module+el8.1.0+3366+6dfb954c
redhat/stax-ex<1.7.7-8.module+el8.1.0+3366+6dfb954c
1.7.7-8.module+el8.1.0+3366+6dfb954c
redhat/velocity<1.7-24.module+el8.1.0+3366+6dfb954c
1.7-24.module+el8.1.0+3366+6dfb954c
redhat/xalan-j2<2.7.1-38.module+el8.1.0+3366+6dfb954c
2.7.1-38.module+el8.1.0+3366+6dfb954c
redhat/xerces-j2<2.11.0-34.module+el8.1.0+3366+6dfb954c
2.11.0-34.module+el8.1.0+3366+6dfb954c
redhat/xml-commons-apis<1.4.01-25.module+el8.1.0+3366+6dfb954c
1.4.01-25.module+el8.1.0+3366+6dfb954c
redhat/xml-commons-resolver<1.2-26.module+el8.1.0+3366+6dfb954c
1.2-26.module+el8.1.0+3366+6dfb954c
redhat/xmlstreambuffer<1.5.4-8.module+el8.1.0+3366+6dfb954c
1.5.4-8.module+el8.1.0+3366+6dfb954c
redhat/xsom<0-19.20110809svn.module+el8.1.0+3366+6dfb954c
0-19.20110809svn.module+el8.1.0+3366+6dfb954c
redhat/jss<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/ldapjdk<4.21.0-2.module+el8.2.0+4573+c3c38c7b
4.21.0-2.module+el8.2.0+4573+c3c38c7b
redhat/pki-core<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/tomcatjss<7.4.1-2.module+el8.2.0+4573+c3c38c7b
7.4.1-2.module+el8.2.0+4573+c3c38c7b
redhat/apache-commons-collections<3.2.2-10.module+el8.1.0+3366+6dfb954c
3.2.2-10.module+el8.1.0+3366+6dfb954c
redhat/apache-commons-lang<2.6-21.module+el8.1.0+3366+6dfb954c
2.6-21.module+el8.1.0+3366+6dfb954c
redhat/bea-stax-api<1.2.0-16.module+el8.1.0+3366+6dfb954c
1.2.0-16.module+el8.1.0+3366+6dfb954c
redhat/glassfish-fastinfoset<1.2.13-9.module+el8.1.0+3366+6dfb954c
1.2.13-9.module+el8.1.0+3366+6dfb954c
redhat/glassfish-jaxb-api<2.2.12-8.module+el8.1.0+3366+6dfb954c
2.2.12-8.module+el8.1.0+3366+6dfb954c
redhat/glassfish-jaxb-core<2.2.11-11.module+el8.1.0+3366+6dfb954c
2.2.11-11.module+el8.1.0+3366+6dfb954c
redhat/glassfish-jaxb-runtime<2.2.11-11.module+el8.1.0+3366+6dfb954c
2.2.11-11.module+el8.1.0+3366+6dfb954c
redhat/glassfish-jaxb-txw2<2.2.11-11.module+el8.1.0+3366+6dfb954c
2.2.11-11.module+el8.1.0+3366+6dfb954c
redhat/jackson-annotations<2.10.0-1.module+el8.2.0+5059+3eb3af25
2.10.0-1.module+el8.2.0+5059+3eb3af25
redhat/jackson-core<2.10.0-1.module+el8.2.0+5059+3eb3af25
2.10.0-1.module+el8.2.0+5059+3eb3af25
redhat/jackson-databind<2.10.0-1.module+el8.2.0+5059+3eb3af25
2.10.0-1.module+el8.2.0+5059+3eb3af25
redhat/jackson-jaxrs-json-provider<2.9.9-1.module+el8.1.0+3832+9784644d
2.9.9-1.module+el8.1.0+3832+9784644d
redhat/jackson-jaxrs-providers<2.9.9-1.module+el8.1.0+3832+9784644d
2.9.9-1.module+el8.1.0+3832+9784644d
redhat/jackson-module-jaxb-annotations<2.7.6-4.module+el8.1.0+3366+6dfb954c
2.7.6-4.module+el8.1.0+3366+6dfb954c
redhat/jakarta-commons-httpclient<3.1-28.module+el8.1.0+3366+6dfb954c
3.1-28.module+el8.1.0+3366+6dfb954c
redhat/javassist<3.18.1-8.module+el8.1.0+3366+6dfb954c
3.18.1-8.module+el8.1.0+3366+6dfb954c
redhat/javassist-javadoc<3.18.1-8.module+el8.1.0+3366+6dfb954c
3.18.1-8.module+el8.1.0+3366+6dfb954c
redhat/pki-servlet<4.0-api-9.0.7-16.module+el8.1.0+3366+6dfb954c
4.0-api-9.0.7-16.module+el8.1.0+3366+6dfb954c
redhat/pki-servlet-engine<9.0.7-16.module+el8.1.0+3366+6dfb954c
9.0.7-16.module+el8.1.0+3366+6dfb954c
redhat/resteasy<3.0.26-3.module+el8.1.0+3366+6dfb954c
3.0.26-3.module+el8.1.0+3366+6dfb954c
redhat/slf4j<1.7.25-4.module+el8.1.0+3366+6dfb954c
1.7.25-4.module+el8.1.0+3366+6dfb954c
redhat/slf4j-jdk14<1.7.25-4.module+el8.1.0+3366+6dfb954c
1.7.25-4.module+el8.1.0+3366+6dfb954c
redhat/stax-ex<1.7.7-8.module+el8.1.0+3366+6dfb954c
1.7.7-8.module+el8.1.0+3366+6dfb954c
redhat/velocity<1.7-24.module+el8.1.0+3366+6dfb954c
1.7-24.module+el8.1.0+3366+6dfb954c
redhat/xalan-j2<2.7.1-38.module+el8.1.0+3366+6dfb954c
2.7.1-38.module+el8.1.0+3366+6dfb954c
redhat/xerces-j2<2.11.0-34.module+el8.1.0+3366+6dfb954c
2.11.0-34.module+el8.1.0+3366+6dfb954c
redhat/xml-commons-apis<1.4.01-25.module+el8.1.0+3366+6dfb954c
1.4.01-25.module+el8.1.0+3366+6dfb954c
redhat/xml-commons-resolver<1.2-26.module+el8.1.0+3366+6dfb954c
1.2-26.module+el8.1.0+3366+6dfb954c
redhat/xmlstreambuffer<1.5.4-8.module+el8.1.0+3366+6dfb954c
1.5.4-8.module+el8.1.0+3366+6dfb954c
redhat/xsom<0-19.20110809svn.module+el8.1.0+3366+6dfb954c
0-19.20110809svn.module+el8.1.0+3366+6dfb954c
redhat/ldapjdk<4.21.0-2.module+el8.2.0+4573+c3c38c7b
4.21.0-2.module+el8.2.0+4573+c3c38c7b
redhat/ldapjdk-javadoc<4.21.0-2.module+el8.2.0+4573+c3c38c7b
4.21.0-2.module+el8.2.0+4573+c3c38c7b
redhat/pki-base<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-base-java<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-ca<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-kra<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-server<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/python3-pki<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/tomcatjss<7.4.1-2.module+el8.2.0+4573+c3c38c7b
7.4.1-2.module+el8.2.0+4573+c3c38c7b
redhat/jss<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/jss-debuginfo<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/jss-debugsource<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/jss-javadoc<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/pki-core-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-core-debugsource<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-symkey<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-symkey-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-tools<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-tools-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/python-nss-debugsource<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python-nss-doc<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python3-nss<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python3-nss-debuginfo<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/jss-debuginfo<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/jss-debugsource<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/jss-javadoc<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/pki-core-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-core-debugsource<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-symkey<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-symkey-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-tools<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-tools-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/python-nss-debugsource<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python-nss-doc<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python3-nss<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python3-nss-debuginfo<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/jss<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/jss-debuginfo<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/jss-debugsource<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/jss-javadoc<4.6.2-4.module+el8.2.0+6123+b4678599
4.6.2-4.module+el8.2.0+6123+b4678599
redhat/pki-core-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-core-debugsource<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-symkey<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-symkey-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-tools<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/pki-tools-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a
10.8.3-1.module+el8.2.0+5925+bad5981a
redhat/python-nss-debugsource<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python-nss-doc<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python3-nss<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python3-nss-debuginfo<1.0.1-10.module+el8.1.0+3366+6dfb954c
1.0.1-10.module+el8.1.0+3366+6dfb954c
redhat/python-nss-debugsource<1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
redhat/python-nss-doc<1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
redhat/python3-nss<1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
redhat/python3-nss-debuginfo<1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
redhat/jss<4.6.2-4.module+el8.2.0+6123+b4678599.aa
4.6.2-4.module+el8.2.0+6123+b4678599.aa
redhat/jss-debuginfo<4.6.2-4.module+el8.2.0+6123+b4678599.aa
4.6.2-4.module+el8.2.0+6123+b4678599.aa
redhat/jss-debugsource<4.6.2-4.module+el8.2.0+6123+b4678599.aa
4.6.2-4.module+el8.2.0+6123+b4678599.aa
redhat/jss-javadoc<4.6.2-4.module+el8.2.0+6123+b4678599.aa
4.6.2-4.module+el8.2.0+6123+b4678599.aa
redhat/pki-core-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a.aa
10.8.3-1.module+el8.2.0+5925+bad5981a.aa
redhat/pki-core-debugsource<10.8.3-1.module+el8.2.0+5925+bad5981a.aa
10.8.3-1.module+el8.2.0+5925+bad5981a.aa
redhat/pki-symkey<10.8.3-1.module+el8.2.0+5925+bad5981a.aa
10.8.3-1.module+el8.2.0+5925+bad5981a.aa
redhat/pki-symkey-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a.aa
10.8.3-1.module+el8.2.0+5925+bad5981a.aa
redhat/pki-tools<10.8.3-1.module+el8.2.0+5925+bad5981a.aa
10.8.3-1.module+el8.2.0+5925+bad5981a.aa
redhat/pki-tools-debuginfo<10.8.3-1.module+el8.2.0+5925+bad5981a.aa
10.8.3-1.module+el8.2.0+5925+bad5981a.aa

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/jss to a version that resolves this vulnerability.

    Fixed in 4.6.2-4.module+el8.2.0+6123+b4678599
  2. Upgrade

    Upgrade redhat/ldapjdk to a version that resolves this vulnerability.

    Fixed in 4.21.0-2.module+el8.2.0+4573+c3c38c7b
  3. Upgrade

    Upgrade redhat/pki-core to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  4. Upgrade

    Upgrade redhat/tomcatjss to a version that resolves this vulnerability.

    Fixed in 7.4.1-2.module+el8.2.0+4573+c3c38c7b
  5. Upgrade

    Upgrade redhat/apache-commons-collections to a version that resolves this vulnerability.

    Fixed in 3.2.2-10.module+el8.1.0+3366+6dfb954c
  6. Upgrade

    Upgrade redhat/apache-commons-lang to a version that resolves this vulnerability.

    Fixed in 2.6-21.module+el8.1.0+3366+6dfb954c
  7. Upgrade

    Upgrade redhat/bea-stax to a version that resolves this vulnerability.

    Fixed in 1.2.0-16.module+el8.1.0+3366+6dfb954c
  8. Upgrade

    Upgrade redhat/glassfish-fastinfoset to a version that resolves this vulnerability.

    Fixed in 1.2.13-9.module+el8.1.0+3366+6dfb954c
  9. Upgrade

    Upgrade redhat/glassfish-jaxb to a version that resolves this vulnerability.

    Fixed in 2.2.11-11.module+el8.1.0+3366+6dfb954c
  10. Upgrade

    Upgrade redhat/glassfish-jaxb-api to a version that resolves this vulnerability.

    Fixed in 2.2.12-8.module+el8.1.0+3366+6dfb954c
  11. Upgrade

    Upgrade redhat/jackson-annotations to a version that resolves this vulnerability.

    Fixed in 2.10.0-1.module+el8.2.0+5059+3eb3af25
  12. Upgrade

    Upgrade redhat/jackson-core to a version that resolves this vulnerability.

    Fixed in 2.10.0-1.module+el8.2.0+5059+3eb3af25
  13. Upgrade

    Upgrade redhat/jackson-databind to a version that resolves this vulnerability.

    Fixed in 2.10.0-1.module+el8.2.0+5059+3eb3af25
  14. Upgrade

    Upgrade redhat/jackson-jaxrs-providers to a version that resolves this vulnerability.

    Fixed in 2.9.9-1.module+el8.1.0+3832+9784644d
  15. Upgrade

    Upgrade redhat/jackson-module-jaxb-annotations to a version that resolves this vulnerability.

    Fixed in 2.7.6-4.module+el8.1.0+3366+6dfb954c
  16. Upgrade

    Upgrade redhat/jakarta-commons-httpclient to a version that resolves this vulnerability.

    Fixed in 3.1-28.module+el8.1.0+3366+6dfb954c
  17. Upgrade

    Upgrade redhat/javassist to a version that resolves this vulnerability.

    Fixed in 3.18.1-8.module+el8.1.0+3366+6dfb954c
  18. Upgrade

    Upgrade redhat/pki-servlet-engine to a version that resolves this vulnerability.

    Fixed in 9.0.7-16.module+el8.1.0+3366+6dfb954c
  19. Upgrade

    Upgrade redhat/python-nss to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c
  20. Upgrade

    Upgrade redhat/resteasy to a version that resolves this vulnerability.

    Fixed in 3.0.26-3.module+el8.1.0+3366+6dfb954c
  21. Upgrade

    Upgrade redhat/slf4j to a version that resolves this vulnerability.

    Fixed in 1.7.25-4.module+el8.1.0+3366+6dfb954c
  22. Upgrade

    Upgrade redhat/stax-ex to a version that resolves this vulnerability.

    Fixed in 1.7.7-8.module+el8.1.0+3366+6dfb954c
  23. Upgrade

    Upgrade redhat/velocity to a version that resolves this vulnerability.

    Fixed in 1.7-24.module+el8.1.0+3366+6dfb954c
  24. Upgrade

    Upgrade redhat/xalan-j2 to a version that resolves this vulnerability.

    Fixed in 2.7.1-38.module+el8.1.0+3366+6dfb954c
  25. Upgrade

    Upgrade redhat/xerces-j2 to a version that resolves this vulnerability.

    Fixed in 2.11.0-34.module+el8.1.0+3366+6dfb954c
  26. Upgrade

    Upgrade redhat/xml-commons-apis to a version that resolves this vulnerability.

    Fixed in 1.4.01-25.module+el8.1.0+3366+6dfb954c
  27. Upgrade

    Upgrade redhat/xml-commons-resolver to a version that resolves this vulnerability.

    Fixed in 1.2-26.module+el8.1.0+3366+6dfb954c
  28. Upgrade

    Upgrade redhat/xmlstreambuffer to a version that resolves this vulnerability.

    Fixed in 1.5.4-8.module+el8.1.0+3366+6dfb954c
  29. Upgrade

    Upgrade redhat/xsom to a version that resolves this vulnerability.

    Fixed in 0-19.20110809svn.module+el8.1.0+3366+6dfb954c
  30. Upgrade

    Upgrade redhat/ldapjdk-javadoc to a version that resolves this vulnerability.

    Fixed in 4.21.0-2.module+el8.2.0+4573+c3c38c7b
  31. Upgrade

    Upgrade redhat/pki-base to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  32. Upgrade

    Upgrade redhat/pki-base-java to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  33. Upgrade

    Upgrade redhat/pki-ca to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  34. Upgrade

    Upgrade redhat/pki-kra to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  35. Upgrade

    Upgrade redhat/pki-server to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  36. Upgrade

    Upgrade redhat/python3-pki to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  37. Upgrade

    Upgrade redhat/bea-stax-api to a version that resolves this vulnerability.

    Fixed in 1.2.0-16.module+el8.1.0+3366+6dfb954c
  38. Upgrade

    Upgrade redhat/glassfish-jaxb-core to a version that resolves this vulnerability.

    Fixed in 2.2.11-11.module+el8.1.0+3366+6dfb954c
  39. Upgrade

    Upgrade redhat/glassfish-jaxb-runtime to a version that resolves this vulnerability.

    Fixed in 2.2.11-11.module+el8.1.0+3366+6dfb954c
  40. Upgrade

    Upgrade redhat/glassfish-jaxb-txw2 to a version that resolves this vulnerability.

    Fixed in 2.2.11-11.module+el8.1.0+3366+6dfb954c
  41. Upgrade

    Upgrade redhat/jackson-jaxrs-json-provider to a version that resolves this vulnerability.

    Fixed in 2.9.9-1.module+el8.1.0+3832+9784644d
  42. Upgrade

    Upgrade redhat/javassist-javadoc to a version that resolves this vulnerability.

    Fixed in 3.18.1-8.module+el8.1.0+3366+6dfb954c
  43. Upgrade

    Upgrade redhat/pki-servlet to a version that resolves this vulnerability.

    Fixed in 4.0-api-9.0.7-16.module+el8.1.0+3366+6dfb954c
  44. Upgrade

    Upgrade redhat/slf4j-jdk14 to a version that resolves this vulnerability.

    Fixed in 1.7.25-4.module+el8.1.0+3366+6dfb954c
  45. Upgrade

    Upgrade redhat/python-nss-debugsource to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c
  46. Upgrade

    Upgrade redhat/python-nss-doc to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c
  47. Upgrade

    Upgrade redhat/python3-nss to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c
  48. Upgrade

    Upgrade redhat/python3-nss-debuginfo to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c
  49. Upgrade

    Upgrade redhat/jss-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.6.2-4.module+el8.2.0+6123+b4678599
  50. Upgrade

    Upgrade redhat/jss-debugsource to a version that resolves this vulnerability.

    Fixed in 4.6.2-4.module+el8.2.0+6123+b4678599
  51. Upgrade

    Upgrade redhat/jss-javadoc to a version that resolves this vulnerability.

    Fixed in 4.6.2-4.module+el8.2.0+6123+b4678599
  52. Upgrade

    Upgrade redhat/pki-core-debuginfo to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  53. Upgrade

    Upgrade redhat/pki-core-debugsource to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  54. Upgrade

    Upgrade redhat/pki-symkey to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  55. Upgrade

    Upgrade redhat/pki-symkey-debuginfo to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  56. Upgrade

    Upgrade redhat/pki-tools to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  57. Upgrade

    Upgrade redhat/pki-tools-debuginfo to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a
  58. Upgrade

    Upgrade redhat/jss to a version that resolves this vulnerability.

    Fixed in 4.6.2-4.module+el8.2.0+6123+b4678599.aa
  59. Upgrade

    Upgrade redhat/jss-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.6.2-4.module+el8.2.0+6123+b4678599.aa
  60. Upgrade

    Upgrade redhat/jss-debugsource to a version that resolves this vulnerability.

    Fixed in 4.6.2-4.module+el8.2.0+6123+b4678599.aa
  61. Upgrade

    Upgrade redhat/jss-javadoc to a version that resolves this vulnerability.

    Fixed in 4.6.2-4.module+el8.2.0+6123+b4678599.aa
  62. Upgrade

    Upgrade redhat/pki-core-debuginfo to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a.aa
  63. Upgrade

    Upgrade redhat/pki-core-debugsource to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a.aa
  64. Upgrade

    Upgrade redhat/pki-symkey to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a.aa
  65. Upgrade

    Upgrade redhat/pki-symkey-debuginfo to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a.aa
  66. Upgrade

    Upgrade redhat/pki-tools to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a.aa
  67. Upgrade

    Upgrade redhat/pki-tools-debuginfo to a version that resolves this vulnerability.

    Fixed in 10.8.3-1.module+el8.2.0+5925+bad5981a.aa
  68. Upgrade

    Upgrade redhat/python-nss-debugsource to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
  69. Upgrade

    Upgrade redhat/python-nss-doc to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
  70. Upgrade

    Upgrade redhat/python3-nss to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
  71. Upgrade

    Upgrade redhat/python3-nss-debuginfo to a version that resolves this vulnerability.

    Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c.aa
  72. Upgrade

    Upgrade pki-core:10.6 to a version that resolves this vulnerability.

    Fixed in 10.6
  73. Upgrade

    Upgrade pki-deps:10.6 to a version that resolves this vulnerability.

    Fixed in 10.6
  74. Upgrade

    Upgrade jackson-databind (Red Hat pki-core/pki-deps release) to a version that resolves this vulnerability.

    Patch CVE-2019-14540

Event History

May 25, 2026
Advisory Published
via Red Hat·10:31 AM
Data Sourced
via Red Hat·10:31 AM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

What is the severity of RHSA-2020:1644?

The severity of RHSA-2020:1644 is categorized as important.

2

How do I fix RHSA-2020:1644?

To fix RHSA-2020:1644, you should update the affected packages to the versions specified in the advisory.

3

Which packages are affected by RHSA-2020:1644?

RHSA-2020:1644 affects multiple packages including jackson-databind, pki-core, and various others listed in the advisory.

4

What are the implications of not addressing RHSA-2020:1644?

Not addressing RHSA-2020:1644 could lead to potential vulnerabilities being exploited, impacting the security of your systems.

5

Is there a workaround for RHSA-2020:1644?

The recommended action for RHSA-2020:1644 is to update the packages as no specific workarounds are provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203