RHSA-2022:7326: Important: pki-core security update
The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.Security Fix(es): pki-core: access to external entities when parsing XML can lead to XXE (CVE-2022-2414) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:7326?
The severity of RHSA-2022:7326 is classified as important.
What vulnerability is addressed in RHSA-2022:7326?
RHSA-2022:7326 addresses the CVE-2022-2414 vulnerability which allows access to external entities when parsing XML, leading to XXE.
How do I fix RHSA-2022:7326?
To fix RHSA-2022:7326, upgrade the affected packages to version 11.0.6-2.el9_0 or later.
Which packages are affected by RHSA-2022:7326?
The affected packages include pki-core, pki-acme, pki-base, pki-ca, pki-server, and several others listed in the advisory.
Is there a workaround for RHSA-2022:7326?
There is no specific workaround documented for RHSA-2022:7326; updating to the recommended version is advised.