RHSA-2022:8915: Important: Red Hat Certificate System 9.7 security update
The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.Security Fix(es): pki-core: access to external entities when parsing XML can lead to XXE (CVE-2022-2414) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Update RHCS version of CA, KRA, OCSP, and TKS so that it can be identified using a browser [RHCS 9.7.z BU 19] (BZ#2136537)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8915?
RHSA-2022:8915 is classified as important due to the potential for XML External Entity (XXE) attacks.
How do I fix RHSA-2022:8915?
To fix RHSA-2022:8915, upgrade the affected packages to the recommended versions: pki-core to 10.5.18-24.el7 or redhat-pki-theme to 10.5.18-16.el7.
Which packages are affected by RHSA-2022:8915?
The affected packages under RHSA-2022:8915 include pki-core, redhat-pki-theme, pki-core-debuginfo, pki-ocsp, pki-tks, and pki-tps.
What vulnerability does RHSA-2022:8915 address?
RHSA-2022:8915 addresses a vulnerability related to XML External Entity (XXE) processing, which can lead to the disclosure of sensitive information.
Is RHSA-2022:8915 related to any specific version of Red Hat?
Yes, RHSA-2022:8915 pertains specifically to Red Hat Enterprise Linux 7 and its related packages.