RHSA-2023:3394: Important: pki-core:10.6 security update
Important: pki-core:10.6 security update
Other sources
The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.Security Fix(es): pki-core: access to external entities when parsing XML can lead to XXE (CVE-2022-2414) pki-core: When using the caServerKeygenDirUserCert profile, user can get certificates for other UIDs by entering name in Subject field (CVE-2022-2393) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jssto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7 - Upgrade
Upgrade
redhat/ldapjdkto a version that resolves this vulnerability.Fixed in 4.23.0-1.module+el8.5.0+11983+6ba118b4 - Upgrade
Upgrade
redhat/pki-coreto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/tomcatjssto a version that resolves this vulnerability.Fixed in 7.7.1-1.module+el8.6.0+13291+248751b1 - Upgrade
Upgrade
redhat/ldapjdk-javadocto a version that resolves this vulnerability.Fixed in 4.23.0-1.module+el8.5.0+11983+6ba118b4 - Upgrade
Upgrade
redhat/pki-acmeto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-baseto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-base-javato a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-cato a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-krato a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-serverto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/python3-pkito a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/jss-debuginfoto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7 - Upgrade
Upgrade
redhat/jss-debugsourceto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7 - Upgrade
Upgrade
redhat/jss-javadocto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7 - Upgrade
Upgrade
redhat/pki-core-debuginfoto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-core-debugsourceto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-symkeyto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-symkey-debuginfoto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-toolsto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/pki-tools-debuginfoto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
redhat/jssto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7.aa - Upgrade
Upgrade
redhat/jss-debuginfoto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7.aa - Upgrade
Upgrade
redhat/jss-debugsourceto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7.aa - Upgrade
Upgrade
redhat/jss-javadocto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7.aa - Upgrade
Upgrade
redhat/pki-core-debuginfoto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17.aa - Upgrade
Upgrade
redhat/pki-core-debugsourceto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17.aa - Upgrade
Upgrade
redhat/pki-symkeyto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17.aa - Upgrade
Upgrade
redhat/pki-symkey-debuginfoto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17.aa - Upgrade
Upgrade
redhat/pki-toolsto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17.aa - Upgrade
Upgrade
redhat/pki-tools-debuginfoto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17.aa - Upgrade
Upgrade
jssto a version that resolves this vulnerability.Fixed in 4.9.3-1.module+el8.6.0+14244+60d461b7 - Upgrade
Upgrade
ldapjdkto a version that resolves this vulnerability.Fixed in 4.23.0-1.module+el8.5.0+11983+6ba118b4 - Upgrade
Upgrade
pki-acmeto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
pki-baseto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
pki-base-javato a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
pki-cato a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
pki-coreto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
pki-krato a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
pki-serverto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
pki-symkeyto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
pki-toolsto a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
python3-pkito a version that resolves this vulnerability.Fixed in 10.12.7-1.module+el8.6.0+18623+dea80f17 - Upgrade
Upgrade
tomcatjssto a version that resolves this vulnerability.Fixed in 7.7.1-1.module+el8.6.0+13291+248751b1
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3394?
The RHSA-2023:3394 vulnerability has been classified as important.
How do I fix RHSA-2023:3394?
To fix RHSA-2023:3394, update to the remedied packages, specifically pki-core version 10.12.7-1.module+el8.6.0+18623+dea80f17.
What vulnerabilities are addressed in RHSA-2023:3394?
RHSA-2023:3394 addresses a vulnerability allowing access to external entities when parsing XML, leading to an XXE attack (CVE-2022-2414).
Which systems are affected by RHSA-2023:3394?
RHSA-2023:3394 affects multiple Red Hat Enterprise Linux products, including versions for Power, ARM 64, and Extended Update Support.
What is CVE-2022-2414 related to RHSA-2023:3394?
CVE-2022-2414 is a vulnerability related to XML external entity (XXE) processing that can be exploited in the Public Key Infrastructure (PKI) Core.