First published: Wed Oct 05 2022(Updated: )
This release of Red Hat build of Eclipse Vert.x 4.3.3 GA includes security updates. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> graphql-java: DoS by malicious query (CVE-2022-37734)</li> <li> snakeyaml: Denial of Service due missing to nested depth limitation for collections. (CVE-2022-25857)</li> <li> snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode (CVE-2022-38749)</li> <li> snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (CVE-2022-38750)</li> <li> snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match (CVE-2022-38751)</li> <li> snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode (CVE-2022-38752)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Vert.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:6757 is classified as important due to the potential Denial of Service vulnerabilities.
To fix RHSA-2022:6757, update your Red Hat build of Eclipse Vert.x to the latest version that addresses the security vulnerabilities.
RHSA-2022:6757 addresses security vulnerabilities including CVE-2022-37734 related to DoS by malicious query in graphql-java and issues in snakeyaml.
No, RHSA-2022:6757 specifically applies to the Red Hat build of Eclipse Vert.x 4.3.3 GA.
RHSA-2022:6757 affects the graphql-java and snakeyaml components within the Red Hat build of Eclipse Vert.x.