First published: Mon Dec 12 2022(Updated: )
The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.<br>Security Fix(es):<br><li> pki-core: access to external entities when parsing XML can lead to XXE (CVE-2022-2414)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Update RHCS version of CA, KRA, OCSP, and TKS so that it can be identified using a browser [RHCS 9.7.z BU 19] (BZ#2136537)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/pki-core | <10.5.18-24.el7 | 10.5.18-24.el7 |
redhat/redhat-pki-theme | <10.5.18-16.el7 | 10.5.18-16.el7 |
redhat/pki-core-debuginfo | <10.5.18-24.el7 | 10.5.18-24.el7 |
redhat/pki-ocsp | <10.5.18-24.el7 | 10.5.18-24.el7 |
redhat/pki-tks | <10.5.18-24.el7 | 10.5.18-24.el7 |
redhat/pki-tps | <10.5.18-24.el7 | 10.5.18-24.el7 |
redhat/redhat-pki-console-theme | <10.5.18-16.el7 | 10.5.18-16.el7 |
redhat/redhat-pki-server-theme | <10.5.18-16.el7 | 10.5.18-16.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.