Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-9058-1

Опубликовано: 15 дек. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-9058-1: prometheus-jmx-exporter security update (IMPORTANT)

[0.12.0-9]

  • Fix CVE-2022-1471 by using SafeConstructor.

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

prometheus-jmx-exporter

0.12.0-9.el8_7

prometheus-jmx-exporter-openjdk11

0.12.0-9.el8_7

prometheus-jmx-exporter-openjdk17

0.12.0-9.el8_7

prometheus-jmx-exporter-openjdk8

0.12.0-9.el8_7

Oracle Linux x86_64

prometheus-jmx-exporter

0.12.0-9.el8_7

prometheus-jmx-exporter-openjdk11

0.12.0-9.el8_7

prometheus-jmx-exporter-openjdk17

0.12.0-9.el8_7

prometheus-jmx-exporter-openjdk8

0.12.0-9.el8_7

Связанные CVE

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 2 лет назад

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVSS3: 9.8
redhat
больше 2 лет назад

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVSS3: 8.3
nvd
больше 2 лет назад

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVSS3: 8.3
debian
больше 2 лет назад

SnakeYaml's Constructor() class does not restrict types which can be i ...

rocky
больше 2 лет назад

Important: prometheus-jmx-exporter security update