RHSA-2021:1263: Important: pki-core:10.6 security and bug fix update
The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.Security Fix(es): pki-core: Unprivileged users can renew any certificate (CVE-2021-20179) pki-core: XSS in the certificate search results (CVE-2020-25715) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): PKI instance creation failed with new 389-ds-base build (BZ#1933147)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jssto a version that resolves this vulnerability.Fixed in 4.6.2-12.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/ldapjdkto a version that resolves this vulnerability.Fixed in 4.21.0-2.module+el8.2.0+6294+b7db4606 - Upgrade
Upgrade
redhat/pki-coreto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/tomcatjssto a version that resolves this vulnerability.Fixed in 7.4.1-2.module+el8.2.0+6294+b7db4606 - Upgrade
Upgrade
redhat/ldapjdk-javadocto a version that resolves this vulnerability.Fixed in 4.21.0-2.module+el8.2.0+6294+b7db4606 - Upgrade
Upgrade
redhat/pki-baseto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-base-javato a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-cato a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-krato a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-serverto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/python3-pkito a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/jss-debuginfoto a version that resolves this vulnerability.Fixed in 4.6.2-12.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/jss-debugsourceto a version that resolves this vulnerability.Fixed in 4.6.2-12.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/jss-javadocto a version that resolves this vulnerability.Fixed in 4.6.2-12.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-core-debuginfoto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-core-debugsourceto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-symkeyto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-symkey-debuginfoto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-toolsto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/pki-tools-debuginfoto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72 - Upgrade
Upgrade
redhat/jssto a version that resolves this vulnerability.Fixed in 4.6.2-12.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/jss-debuginfoto a version that resolves this vulnerability.Fixed in 4.6.2-12.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/jss-debugsourceto a version that resolves this vulnerability.Fixed in 4.6.2-12.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/jss-javadocto a version that resolves this vulnerability.Fixed in 4.6.2-12.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/pki-core-debuginfoto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/pki-core-debugsourceto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/pki-symkeyto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/pki-symkey-debuginfoto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/pki-toolsto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
redhat/pki-tools-debuginfoto a version that resolves this vulnerability.Fixed in 10.8.3-6.module+el8.2.0+10554+cf83aa72.aa - Upgrade
Upgrade
pki-coreto a version that resolves this vulnerability.Fixed in 10.6 - Upgrade
Upgrade
pki-coreto a version that resolves this vulnerability.Patch CVE-2020-25715 - Upgrade
Upgrade
pki-coreto a version that resolves this vulnerability.Patch CVE-2021-20179 - Upgrade
Upgrade
pki-coreto a version that resolves this vulnerability.Patch BZ#1933147
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:1263?
RHSA-2021:1263 is classified as important severity.
How do I fix RHSA-2021:1263?
To fix RHSA-2021:1263, upgrade the affected packages to their respective versions detailed in the advisory.
Which packages are affected by RHSA-2021:1263?
Affected packages include pki-core, jss, ldapjdk, and others listed in the advisory.
What vulnerabilities are addressed in RHSA-2021:1263?
RHSA-2021:1263 addresses vulnerabilities such as unprivileged certificate renewal and XSS in certificate search results.
Is a system reboot required after applying the RHSA-2021:1263 fix?
A system reboot is not required following the installation of the patch for RHSA-2021:1263.