RHSA-2023:1966: Important: pki-core:10.6 security update
The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.Security Fix(es): pki-core: access to external entities when parsing XML can lead to XXE (CVE-2022-2414) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jssto a version that resolves this vulnerability.Fixed in 4.8.1-2.module+el8.4.0+10451+3e5b5448 - Upgrade
Upgrade
redhat/ldapjdkto a version that resolves this vulnerability.Fixed in 4.22.0-1.module+el8.3.0+6784+6e1e4c62 - Upgrade
Upgrade
redhat/pki-coreto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/tomcatjssto a version that resolves this vulnerability.Fixed in 7.6.1-1.module+el8.4.0+8778+d07929ff - Upgrade
Upgrade
redhat/jss-debuginfoto a version that resolves this vulnerability.Fixed in 4.8.1-2.module+el8.4.0+10451+3e5b5448 - Upgrade
Upgrade
redhat/jss-debugsourceto a version that resolves this vulnerability.Fixed in 4.8.1-2.module+el8.4.0+10451+3e5b5448 - Upgrade
Upgrade
redhat/jss-javadocto a version that resolves this vulnerability.Fixed in 4.8.1-2.module+el8.4.0+10451+3e5b5448 - Upgrade
Upgrade
redhat/ldapjdk-javadocto a version that resolves this vulnerability.Fixed in 4.22.0-1.module+el8.3.0+6784+6e1e4c62 - Upgrade
Upgrade
redhat/pki-acmeto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-baseto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-base-javato a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-cato a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-core-debuginfoto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-core-debugsourceto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-krato a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-serverto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-symkeyto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-symkey-debuginfoto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-toolsto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/pki-tools-debuginfoto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/python3-pkito a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3 - Upgrade
Upgrade
redhat/jssto a version that resolves this vulnerability.Fixed in 4.8.1-2.module+el8.4.0+10451+3e5b5448.aa - Upgrade
Upgrade
redhat/jss-debuginfoto a version that resolves this vulnerability.Fixed in 4.8.1-2.module+el8.4.0+10451+3e5b5448.aa - Upgrade
Upgrade
redhat/jss-debugsourceto a version that resolves this vulnerability.Fixed in 4.8.1-2.module+el8.4.0+10451+3e5b5448.aa - Upgrade
Upgrade
redhat/jss-javadocto a version that resolves this vulnerability.Fixed in 4.8.1-2.module+el8.4.0+10451+3e5b5448.aa - Upgrade
Upgrade
redhat/pki-core-debuginfoto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3.aa - Upgrade
Upgrade
redhat/pki-core-debugsourceto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3.aa - Upgrade
Upgrade
redhat/pki-symkeyto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3.aa - Upgrade
Upgrade
redhat/pki-symkey-debuginfoto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3.aa - Upgrade
Upgrade
redhat/pki-toolsto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3.aa - Upgrade
Upgrade
redhat/pki-tools-debuginfoto a version that resolves this vulnerability.Fixed in 10.10.5-6.module+el8.4.0+17580+3370c7a3.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1966?
RHSA-2023:1966 is classified as important due to the risk of XML External Entity (XXE) attacks.
How do I fix RHSA-2023:1966?
To fix RHSA-2023:1966, update the affected packages to the recommended fixed versions provided in the advisory.
What packages are affected by RHSA-2023:1966?
The affected packages in RHSA-2023:1966 include pki-core, ldapjdk, jss, and tomcatjss among others.
What vulnerabilities are addressed in RHSA-2023:1966?
RHSA-2023:1966 addresses the vulnerability of unauthorized access to external entities when parsing XML, known as CVE-2022-2414.
When was RHSA-2023:1966 released?
RHSA-2023:1966 was released to address security vulnerabilities that impact Red Hat Certificate System.