Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-3061

Опубликовано: 24 мая 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-3061: pki-core:10.6 and pki-deps:10.6 security update (MODERATE)

apache-commons-collections apache-commons-lang apache-commons-net bea-stax fasterxml-oss-parent [49-1]

  • Rebase to upstream version 49

[26-6]

[26-5]

  • Fix license tag

[26-4]

[26-3]

[26-2]

  • Remove site-plugin from build

[26-1]

  • update to 26

[24-3]

[24-2]

  • disable maven-enforcer-plugin support

[24-1]

  • update to 24

[18e-2]

[18e-1]

  • update to 18e

[16-2]

  • remove com.google.code.maven-replacer-plugin:replacer references

[16-1]

  • update to 16

[11-4]

[11-3]

  • Rebuild to regenerate Maven auto-requires

[11-2]

[11-1]

  • update to 11

[10-2]

  • switch to XMvn
  • minor changes to adapt to current guideline

[10-1]

  • update to 10

[4-3]

[4-2]

[4-1]

  • update to 4

[3-1]

  • initial rpm

glassfish-fastinfoset glassfish-jaxb-api glassfish-jaxb [2.2.11-12]

  • Update requiremnts to avoid conflicts with jaxb module packages

jackson-annotations [2.14.2-1]

  • Rebase to upstream version 2.14.2

jackson-bom [2.14.2-1]

  • Rebase to upstream version 2.14.2

jackson-core [2.14.2-1]

  • Rebase to upstream version 2.14.2

jackson-databind [2.14.2-1]

  • Rebase to upstream version 2.14.2

jackson-jaxrs-providers [2.14.2-1]

  • Rebase to upstream version 2.14.2

jackson-modules-base [2.14.2-2]

  • Remove patch for java 11

[2.14.2-1]

  • Rebase to upstream version 2.14.2

[2.14.1-1]

  • Update to version 2.14.1
  • Resolves: #2070122

[2.11.4-8]

  • Drop jaxb-runtime dependency

[2.11.4-7]

  • Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688

[2.11.4-6]

  • Drop jackson-module-afterburner, jackson-module-guice, jackson-module-mrbean, jackson-module-osgi, jackson-module-paranamer, and jackson-module-javadoc

[2.11.4-5]

  • Add Obsoletes and Conflicts

[2.11.4-4]

  • Rename subpackages to pki-jackson

[2.11.4-3]

  • Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937

[2.11.4-2]

[2.11.4-1]

  • Update to version 2.11.4.

[2.11.3-1]

  • Update to version 2.11.3.

[2.11.2-1]

  • Update to version 2.11.2.

[2.11.1-3]

[2.11.1-2]

[2.11.1-1]

  • Update to version 2.11.1.

[2.11.0-1]

  • Update to version 2.11.0.

[2.10.4-1]

  • Update to version 2.10.4.

[2.10.3-1]

  • Update to version 2.10.3.

[2.10.2-2]

[2.10.2-1]

  • Update to version 2.10.2.

[2.10.1-1]

  • Update to version 2.10.1.

jackson-parent [2.14-1]

  • Rebase to upstream version 2.14

[2.10-1]

  • Update to latest upstream release

[2.9.1.2-1]

  • Update to latest upstream release

[2.9.1-2]

[2.9.1-1]

  • Update to latest upstream release

[2.7-3.1]

[2.7-2.1]

[2.7-1.1]

  • update to 2.7-1

[2.6.2-2]

[2.6.2-1]

  • update to 2.6.2

[2.5-2]

[2.5-1]

  • update to 2.5

[2.4.1-1]

  • initial rpm

jakarta-commons-httpclient javassist pki-servlet-engine [1:9.0.62-1]

  • Bump version number to avoid conflicts with tomcat

[1:9.0.30-4]

  • Convert pki-servlet-engine into an alias for tomcat

[1:9.0.30-3]

  • Reverts: rhbz#1969366 as it causes other issues

[1:9.0.30-2]

  • Resolves: rhbz#1969366 CA instance installation fails with error message

[1:9.0.30-1]

  • Resolves: rhbz#1721684 Rebase pki-servlet-engine to 9.0.30
  • Update to JWS 5.3.0 distribution
  • Remove new dependencies that PKI doesn't need (and are not provided by RHEL 8)

[1:9.0.7-16]

  • Obsoleted pki-servlet-container

[1:9.0.7-15]

  • Rename pki-servlet-container into pki-servlet-engine

[1:9.0.7-14]

  • Update to JWS 5.0.2 distribution
  • Resolves: rhbz#1658846 CVE-2018-8034 pki-servlet-container: tomcat: host name verification missing in WebSocket client
  • Resolves: rhbz#1579614 CVE-2018-8014 pki-servlet-container: tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
  • Resolves: rhbz#1619232 - CVE-2018-8037 pki-servlet-container: tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up
  • Resolves: rhbz#1641874 - CVE-2018-11784 pki-servlet-container: tomcat: Open redirect in default servlet

[1:9.0.7-13]

  • Reinstate Maven artifacts and fix maven-metadata JAR path

[1:9.0.7-12]

  • Add missing BuildRequires: systemd-units

[1:9.0.7-11]

  • Resolves: rhbz#1594139 Cleanup Provides and Requires

[1:9.0.7-10]

  • Create packages for FreeIPA that wrap the JWS distribution of Tomcat

relaxngDatatype slf4j [0:1.7.25-4]

  • Disallow EventData deserialization by default (CVE-2018-8088)
  • Resolves rhbz#1549928

[0:1.7.25-3]

[0:1.7.25-2]

[0:1.7.25-1]

  • Update to upstream version 1.7.25

[0:1.7.22-4]

  • Avoid absolute paths

[0:1.7.22-3]

  • Avoid literal carriage return
  • Remove Group tag

[0:1.7.22-2]

[0:1.7.22-1]

  • Update to upstream version 1.7.22

[0:1.7.21-4]

  • Install source JARs in separate package

[0:1.7.21-3]

  • Remove build-requires on perl

[0:1.7.21-2]

  • Fix build issue with maven-jar-plugin 3.0.0

[0:1.7.21-1]

  • Update to upstream version 1.7.21

[0:1.7.20-1]

  • Update to upstream version 1.7.20

[0:1.7.19-1]

  • Update to upstream version 1.7.19

[0:1.7.18-1]

  • Update to upstream version 1.7.18

[0:1.7.17-1]

  • Update to upstream version 1.7.17

[0:1.7.16-1]

  • Update to upstream version 1.7.16

[0:1.7.14-2]

[0:1.7.14-1]

  • Update to upstream version 1.7.14

[0:1.7.13-1]

  • Update to upstream version 1.7.13

[0:1.7.12-3]

  • List manual files in %files section

[0:1.7.12-2]

[0:1.7.12-1]

  • Update to upstream version 1.7.12

[0:1.7.10-1]

  • Update to upstream version 1.7.10

[0:1.7.7-3]

  • Remove workaround for MSHARED-325

[0:1.7.7-2]

[0:1.7.7-1]

  • Update to upstream version 1.7.7

[0:1.7.6-5]

  • Disable filtering of bundled JavaScript binaries
  • Resolves: rhbz#1078536

[0:1.7.6-4]

  • Merge api, simple and nop back into main package
  • Remove parent, migrator and site subpackages

[0:1.7.6-3]

  • Split into subpackages

[0:1.7.6-2]

  • Remove wagon-ssh build extension
  • Disable slf4j-android module

[0:1.7.6-2]

  • Use Requires: java-headless rebuild (#1067528)

[0:1.7.6-1]

  • Update to upstream version 1.7.6

[0:1.7.5-3]

  • Install manual to versionless docdir (#993551)

[0:1.7.5-2]

[0:1.7.5-1]

  • Update to upstream version 1.7.5

[0:1.7.4-1]

  • Update to upstream version 1.7.4

[0:1.7.3-1]

  • Update to upstream version 1.7.3

[0:1.7.2-9]

[0:1.7.2-8]

[0:1.7.2-7]

  • Fix install location of manual

[0:1.7.2-6]

  • Rebuild to generate maven provides

[0:1.7.2-5]

  • Build with xmvn

[0:1.7.2-4]

  • Install Apache license file
  • Resolves: rhbz#878996

[0:1.7.2-3]

  • Avoid cyclic OSGi dependencies

[0:1.7.2-2]

  • Fix license to ASL 2.0 and MIT
  • Update to add_maven_depmap macro
  • Use generated .mfiles list
  • Small packaging cleanups

[0:1.7.2-1]

  • Update to upstream version 1.7.2

[0:1.7.1-1]

  • Update to upstream version 1.7.1

[0:1.7.0-1]

  • Update to upstream version 1.7.0

[0:1.6.6-2]

[0:1.6.6-1]

  • Update to upstream version 1.6.6
  • Convert patches to POM macros

[0:1.6.1-5]

  • Crosslink with local JDK API docs.

[0:1.6.1-4]

  • Specify explicit source encoding to fix build with Java 1.7.
  • Remove no longer needed javadoc dir upgrade hack.

[0:1.6.1-3]

  • Build with maven 3.x.

[0:1.6.1-2]

[0:1.6.1-1]

  • Update to new upstream version.
  • Various guidelines fixes.

[0:1.5.11-3]

  • Add maven-site-pugin BR.
  • Use new package names.

[0:1.5.11-2]

  • Skip installing tests jar that is no longer produced.
  • Use javadoc aggregate.
  • Use mavenpomdir macro.

[0:1.5.11-1]

  • Update to 1.5.11.
  • Drop depmap and component info files.

[0:1.5.10-5]

  • Require cal10n

[0:1.5.10-4]

  • Fix javadoc files.

[0:1.5.10-3]

  • BR maven-plugin-build-helper.

[0:1.5.10-2]

  • BR cal10n.

[0:1.5.10-1]

  • Update to upstream 1.5.10.

[0:1.5.8-5]

  • Skip tests.

[0:1.5.8-4]

  • Fix other line lenghts.

[0:1.5.8-3]

  • Fix permissions.
  • Fixed descriptions.
  • Fix file lengths.

[0:1.5.8-2]

  • Adapt for Fedora.

[0:1.5.8-1]

  • 1.5.8
  • Replace slf4j-1.5.6-integration-tests-current-only.patch with slf4j-1.5.8-skip-integration-tests.patch because of the failure of 'testMatch'

[0:1.5.6-2]

  • Add -ext jar, depmap and pom
  • Save jcl104-over-slf4j as symlink

[0:1.5.6-1]

  • 1.5.6
  • add repolib
  • fix file eol
  • fix Release tag

[0:1.5.2-2]

  • use excalibur for avalon
  • remove javadoc scriptlets
  • GCJ fixes
  • fix maven directory ownership
  • fix -bc --short-circuit by moving some of %build to %prep

[0:1.5.2-1.jpp5]

  • 1.5.2

[0:1.4.2-2jpp]

  • Fix macro misprint
  • Add maven2-plugin BRs

[0:1.4.2-1jpp]

  • Upgrade to 1.4.2
  • Build with maven2
  • Add poms and depmap frags
  • Add gcj_support option

[0:1.0-0.rc5.1jpp]

  • First JPackage release.

stax-ex velocity xalan-j2 xerces-j2 xml-commons-apis [1.4.01-25]

[1.4.01-24]

  • Elimitate race condition when injecting JAR manifest
  • Resolves: rhbz#1495249

[1.4.01-23]

[1.4.01-22]

  • Update to current packaging guidelines

[1.4.01-21]

[1.4.01-20]

[1.4.01-19]

[1.4.01-18]

[1.4.01-17]

  • Don't generate duplicate Maven metadata

[1.4.01-16]

  • Use .mfiles generated during build

[1.4.01-15]

  • Use Requires: java-headless rebuild (#1067528)

[1.4.01-14]

  • Fix FTBFS.

[1.4.01-13]

[1.4.01-12]

  • Update manifest to match Eclipse version (Resolved: rhbz#964039).

[1.4.01-11]

  • Add Require-Bundle: system.bundle to manifest
  • Resolves: rhbz#917659

[1.4.01-10]

[1.4.01-9]

  • Add additional maven depmap

[1.4.01-8]

  • Remove osgi(system.bundle) requirement from manifest

[1.4.01-7]

[1.4.01-6]

[1.4.01-5]

  • Add missing packages to manifest - javax.xml.stream, javax.xml.stream.events, javax.xml.stream.util, javax.xml.transform.stax (bug #743360)

[1.4.01-4]

  • Add maven metadata
  • Few guidelines tweaks (buildroot, clean, defattr)
  • Versionless jars & javadocs

[1.4.01-3]

[1.4.01-2]

  • Fix FTBFS and rpmlint warnings.
  • Don't package javadoc in manual package.

[0:1.4.01-1]

  • Update to 1.4.01.

[0:1.3.04-3.5]

[0:1.3.04-2.5]

[0:1.3.04-1.5]

  • Add osgi metadata to the ext jar too.

[0:1.3.04-1.4]

  • Add osgi metadata.

[0:1.3.04-1.3]

  • Remove natively compiled bits from the javadoc package (462809)

[0:1.3.04-1.2]

  • drop repotag
  • fix license tag

[0:1.3.04-1jpp.1]

  • Autorebuild for GCC 4.3

[0:1.3.04-0jpp.1]

  • Update to 1.3.04

[0:1.3.03-0jpp.1]

  • Split xml-commons package up into 2 separate package: xml-commons-apis and xml-commons-which.

[0:1.3.02-0.b2.7jpp.10]

  • Add missing Requires for post and postun javadoc sections

[0:1.3.02-0.b2.7jpp_9fc]

  • Rebuilt

[0:1.3.02-0.b2.7jpp_8fc]

  • rebuild

[0:1.3.02-0.b2.7jpp_7fc]

  • stop scriptlet spew

[0:1.3.02-0.b2.7jpp_6fc]

  • Updated to 1.3

[0:1.0-0.b2.7jpp_5fc]

  • bump again for double-long bug on ppc(64)

[0:1.0-0.b2.7jpp_4fc]

  • rebuilt again
  • rebuilt for new gcj
  • rebuilt

[0:1.0-0.b2.7jpp_3fc]

  • Build on ia64, ppc64, s390 and s390x.
  • Switch to aot-compile-rpm (also BC-compiles the which jar).

[0:1.0-0.b2.7jpp_2fc]

  • Remove all prebuilt stuff from the tarball.

[0:1.0-0.b2.7jpp_1fc]

  • Upgrade to 1.0-0.b2.7jpp.
  • Remove now-unnecessary workaround for #130162.
  • Rearrange how BC-compiled stuff is built and installed.

[0:1.0-0.b2.6jpp_13fc]

  • Add alpha to the list of build architectures (#157522).
  • Use absolute paths for rebuild-gcj-db.

[0:1.0-0.b2.6jpp_12fc]

  • Add dependencies for %post and %postun scriptlets (#156901).

[0:1.0-0.b2.6jpp_11fc]

  • BC-compile the API jar.

[0:1.0-0.b2.6jpp_10fc]

  • Remove gcj endorsed dir support (#155693).

[0:1.0-0.b2.6jpp_9fc]

  • Provide a default transformer when running under libgcj.

[0:1.0-0.b2.6jpp_8fc]

  • Provide a default DOM builder when running under libgcj (#155693).

[0:1.0-0.b2.6jpp_7fc]

  • Provide a default SAX parser when running under libgcj (#155693).

[0:1.0-0.b2.6jpp_6fc]

  • Add gcj endorsed dir support.

[0:1.0-0.b2.6jpp_5fc]

  • Sync with RHAPS.

[0:1.0-0.b2.6jpp_4fc]

  • Build into Fedora.

[0:1.0-0.b2.6jpp_3fc]

  • Bootstrap into Fedora.

[0:1.0-0.b2.6jpp_3rh]

  • add coreutils BuildRequires

[0:1.0-0.b2.6jpp_2rh]

  • RH vacuuming part II

[0:1.0-0.b2.6jpp_1rh]

  • RH vacuuming

xml-commons-resolver xmlstreambuffer xsom jss [4.11.0-1]

  • Rebase to JSS 4.11.0

[4.10.0-0.1]

  • Rebase to JSS 4.10.0-alpha1

[4.9.8-1]

  • Rebase to JSS 4.9.8

[4.9.4-1]

  • Rebase to JSS 4.9.4
  • Bug 2013674 - JSS cannot be properly initialized after using another NSS-backed security provider

[4.9.3-1]

  • Rebase to JSS 4.9.3
  • Bug 2046022 - CVE-2021-4213 pki-core:10.6/jss: memory leak in TLS connection leads to OOM [rhel-8]

[4.9.2-1]

  • Rebase to JSS 4.9.2

[4.9.1-1]

  • Rebase to JSS 4.9.1

[4.9.0-1]

  • Rebase to JSS 4.9.0

[4.9.0-0.2]

  • Rebase to JSS 4.9.0-alpha2

[4.9.0-0.1]

  • Rebase to JSS 4.9.0-alpha1

[4.8.1-1]

  • Rebase to upstream JSS v4.8.1
  • Red Hat Bugilla #1908541 - jss broke SCEP - missing PasswordChallenge class
  • Red Hat Bugilla #1489256 - [RFE] jss should support RSA with OAEP padding

[4.8.0-2]

  • Only check PKCS11Constants on beta builds
  • Bump tomcatjss, pki-core conflicts due to lang3

[4.8.0-1]

  • Rebase to upstream JSS v4.8.0

[4.8.0-0.1]

  • Rebase to upstream JSS v4.8.0-b1

[4.7.3-1]

  • Rebase to upstream stable release JSS v4.7.3
  • Red Hat Bugzilla #1873235 - Fix SSL_ERROR_INAPPROPRIATE_FALLBACK_ALERT in pki ca-user-cert-add

[4.7.2-1]

  • Rebase to upstream stable release JSS v4.7.2
  • Red Hat Bugzilla #1822246 - Fix SSLSocket NULL pointer deference after close

[4.7.1-1]

  • Rebase to upstream stable release JSS v4.7.1

[4.7.0-1]

  • Rebase to upstream stable release JSS v4.7.0
  • Fixed TestSSLEngine

[4.7.0-0.4]

  • Rebased to JSS 4.7.0-b4

[4.7.0-0.3]

  • Rebased to JSS 4.7.0-b3

[4.7.0-0.1]

  • Rebased to JSS 4.7.0-b1

[4.6.2-4]

  • Red Hat Bugzilla #1807371 - KRA-HSM: Async and sync key recovery using kra agent web is failing

[4.6.2-3]

  • Red Hat Bugzilla #1807371 - KRA-HSM: Async and sync key recovery using kra agent web is failing

[4.6.2-2]

  • Red Hat Bugzilla #1730767 - JSS: Wrap NSS CMAC + KDF implementations
  • Rebased to JSS 4.6.2

[4.6.0-5]

  • Red Hat Bugzilla #1747987 - CVE 2019-14823 jss: OCSP policy 'Leaf and Chain' implicitly trusts the root certificate

[4.6.0-4]

  • Red Hat Bugzilla #1698059 - pki-core implements crypto

[4.6.0-3]

  • Red Hat Bugzilla #1721135 - JSS - LD_FLAGS support

[4.6.0-2]

  • Minor updates to release

[4.6.0-1]

  • Rebased to JSS 4.6.0

[4.5.3-1]

  • Rebased to JSS 4.5.3

[4.5.0-1]

  • Rebased to JSS 4.5.0

[4.5.0-0.6]

  • Rebased to JSS 4.5.0-b1

[4.5.0-0.5]

  • Red Hat Bugzilla #1612063 - Do not override system crypto policy (support TLS 1.3)

[4.5.0-0.4]

  • Rebased to JSS 4.5.0-a4
  • Red Hat Bugzilla #1604462 - jss: FTBFS in Fedora rawhide

[4.5.0-0.3]

  • Rebased to JSS 4.5.0-a3

[4.5.0-0.2]

  • Rebased to JSS 4.5.0-a2

[4.5.0-0.1]

  • Rebased to JSS 4.5.0-a1

ldapjdk [4.24.0-1]

  • Rebase to LDAP SDK 4.24.0

[4.24.0-0.1]

  • Rebase to LDAP SDK 4.24.0-alpha1

[4.23.0-1]

  • Rebase to LDAP SDK 4.23.0

[4.23.0-0.1]

  • Rebase to LDAP SDK 4.23.0-alpha1

[4.22.0-1]

  • Rebase to LDAP SDK 4.22.0

[4.21.0-2]

  • Bump min required JSS version to 4.6.0

[4.21.0-1]

  • Rebase to LDAP SDK 4.21.0

pki-core [10.15.0-1.0.1]

  • Remove upstream reference

[10.15.0-1]

  • Rebase to PKI 10.15.0

[10.15.0-0.1]

  • Rebase to PKI 10.15.0-alpha1

[10.14.3-2]

  • Replace pki-servlet-engine with tomcat

resteasy [3.0.26-7]

  • RHEL-16724: Replace pki-servlet-4.0-api with tomcat-servlet-4.0-api

tomcatjss [7.8.0-1]

  • Rebase to TomcatJSS 7.8.0

[7.8.0-0.1]

  • Rebase to TomcatJSS 7.8.0-alpha1

[7.7.3-1]

  • Replace pki-servlet-engine with tomcat

[7.7.1-1]

  • Rebase to TomcatJSS 7.7.1

[7.7.0-1]

  • Rebase to TomcatJSS 7.7.0

[7.7.0-0.1]

  • Rebase to TomcatJSS 7.7.0-alpha1

[7.6.1-1]

  • Rebase to TomcatJSS 7.6.1

[7.6.0-2]

  • Bump dependency to JSS 4.8.0
  • Remove unsupported platforms

[7.6.0-1]

  • Rebase to TomcatJSS 7.6.0

[7.5.0-1]

  • Rebase to TomcatJSS 7.5.0

[7.5.0-0.2]

  • Rebase to TomcatJSS 7.5.0-a2

[7.5.0-0.1]

  • Rebase to TomcatJSS 7.5.0-a1

[7.4.1-2]

  • Bump dependency to JSS 4.6.0

[7.4.1-1]

  • Rebase to TomcatJSS 7.4.1

[7.4.0-1]

  • Rebase to TomcatJSS 7.4.0

[7.3.6-1]

  • Rebase to TomcatJSS 7.3.6

[7.3.5-1]

  • Rebase to TomcatJSS 7.3.5

[7.3.4-1]

  • Rebase to TomcatJSS 7.3.4

[7.3.3-2]

  • Red Hat Bugzilla #1612063 - Do not override system crypto policy (support TLS 1.3)

[7.3.3-1]

  • Rebase to TomcatJSS 7.3.3

[7.3.2-1]

  • Rebase to TomcatJSS 7.3.2

[7.3.1-1]

  • Fix Tomcat dependencies
  • Rebase to TomcatJSS 7.3.1

[7.3.0-1]

  • Clean up spec file
  • Rebase to TomcatJSS 7.3.0 final

[7.3.0-0.2]

  • Rebase to TomcatJSS 7.3.0 beta

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module pki-core:10.6 is enabled

idm-jss

4.11.0-1.module+el8.10.0+90282+4ef18d4b

idm-jss-javadoc

4.11.0-1.module+el8.10.0+90282+4ef18d4b

idm-ldapjdk

4.24.0-1.module+el8.10.0+90282+4ef18d4b

idm-ldapjdk-javadoc

4.24.0-1.module+el8.10.0+90282+4ef18d4b

idm-pki-acme

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-base

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-base-java

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-ca

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-kra

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-server

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-symkey

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-tools

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-tomcatjss

7.8.0-1.module+el8.10.0+90282+4ef18d4b

python3-idm-pki

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

resteasy

3.0.26-7.module+el8.10.0+90282+4ef18d4b

resteasy-javadoc

3.0.26-7.module+el8.10.0+90282+4ef18d4b

Module pki-deps:10.6 is enabled

apache-commons-collections

3.2.2-10.module+el8.10.0+90302+23fbc0c1

apache-commons-lang

2.6-21.module+el8.10.0+90302+23fbc0c1

apache-commons-net

3.6-3.module+el8.10.0+90302+23fbc0c1

bea-stax-api

1.2.0-16.module+el8.10.0+90302+23fbc0c1

fasterxml-oss-parent

49-1.module+el8.10.0+90302+23fbc0c1

glassfish-fastinfoset

1.2.13-9.module+el8.10.0+90302+23fbc0c1

glassfish-jaxb-api

2.2.12-8.module+el8.10.0+90302+23fbc0c1

glassfish-jaxb-core

2.2.11-12.module+el8.10.0+90302+23fbc0c1

glassfish-jaxb-runtime

2.2.11-12.module+el8.10.0+90302+23fbc0c1

glassfish-jaxb-txw2

2.2.11-12.module+el8.10.0+90302+23fbc0c1

jackson-annotations

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-bom

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-core

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-databind

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-jaxrs-json-provider

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-jaxrs-providers

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-module-jaxb-annotations

2.14.2-2.module+el8.10.0+90302+23fbc0c1

jackson-modules-base

2.14.2-2.module+el8.10.0+90302+23fbc0c1

jackson-parent

2.14-1.module+el8.10.0+90302+23fbc0c1

jakarta-commons-httpclient

3.1-28.module+el8.10.0+90302+23fbc0c1

javassist

3.18.1-8.module+el8.10.0+90302+23fbc0c1

javassist-javadoc

3.18.1-8.module+el8.10.0+90302+23fbc0c1

pki-servlet-engine

9.0.62-1.module+el8.10.0+90302+23fbc0c1

relaxngDatatype

2011.1-7.module+el8.10.0+90302+23fbc0c1

slf4j

1.7.25-4.module+el8.10.0+90302+23fbc0c1

slf4j-jdk14

1.7.25-4.module+el8.10.0+90302+23fbc0c1

stax-ex

1.7.7-8.module+el8.10.0+90302+23fbc0c1

velocity

1.7-24.module+el8.10.0+90302+23fbc0c1

xalan-j2

2.7.1-38.module+el8.10.0+90302+23fbc0c1

xerces-j2

2.11.0-34.module+el8.10.0+90302+23fbc0c1

xml-commons-apis

1.4.01-25.module+el8.10.0+90302+23fbc0c1

xml-commons-resolver

1.2-26.module+el8.10.0+90302+23fbc0c1

xmlstreambuffer

1.5.4-8.module+el8.10.0+90302+23fbc0c1

xsom

0-19.20110809svn.module+el8.10.0+90302+23fbc0c1

Oracle Linux x86_64

Module pki-core:10.6 is enabled

idm-jss

4.11.0-1.module+el8.10.0+90282+4ef18d4b

idm-jss-javadoc

4.11.0-1.module+el8.10.0+90282+4ef18d4b

idm-ldapjdk

4.24.0-1.module+el8.10.0+90282+4ef18d4b

idm-ldapjdk-javadoc

4.24.0-1.module+el8.10.0+90282+4ef18d4b

idm-pki-acme

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-base

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-base-java

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-ca

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-kra

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-server

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-symkey

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-pki-tools

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

idm-tomcatjss

7.8.0-1.module+el8.10.0+90282+4ef18d4b

python3-idm-pki

10.15.0-1.0.1.module+el8.10.0+90282+4ef18d4b

resteasy

3.0.26-7.module+el8.10.0+90282+4ef18d4b

resteasy-javadoc

3.0.26-7.module+el8.10.0+90282+4ef18d4b

Module pki-deps:10.6 is enabled

apache-commons-collections

3.2.2-10.module+el8.10.0+90302+23fbc0c1

apache-commons-lang

2.6-21.module+el8.10.0+90302+23fbc0c1

apache-commons-net

3.6-3.module+el8.10.0+90302+23fbc0c1

bea-stax-api

1.2.0-16.module+el8.10.0+90302+23fbc0c1

fasterxml-oss-parent

49-1.module+el8.10.0+90302+23fbc0c1

glassfish-fastinfoset

1.2.13-9.module+el8.10.0+90302+23fbc0c1

glassfish-jaxb-api

2.2.12-8.module+el8.10.0+90302+23fbc0c1

glassfish-jaxb-core

2.2.11-12.module+el8.10.0+90302+23fbc0c1

glassfish-jaxb-runtime

2.2.11-12.module+el8.10.0+90302+23fbc0c1

glassfish-jaxb-txw2

2.2.11-12.module+el8.10.0+90302+23fbc0c1

jackson-annotations

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-bom

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-core

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-databind

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-jaxrs-json-provider

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-jaxrs-providers

2.14.2-1.module+el8.10.0+90302+23fbc0c1

jackson-module-jaxb-annotations

2.14.2-2.module+el8.10.0+90302+23fbc0c1

jackson-modules-base

2.14.2-2.module+el8.10.0+90302+23fbc0c1

jackson-parent

2.14-1.module+el8.10.0+90302+23fbc0c1

jakarta-commons-httpclient

3.1-28.module+el8.10.0+90302+23fbc0c1

javassist

3.18.1-8.module+el8.10.0+90302+23fbc0c1

javassist-javadoc

3.18.1-8.module+el8.10.0+90302+23fbc0c1

pki-servlet-engine

9.0.62-1.module+el8.10.0+90302+23fbc0c1

relaxngDatatype

2011.1-7.module+el8.10.0+90302+23fbc0c1

slf4j

1.7.25-4.module+el8.10.0+90302+23fbc0c1

slf4j-jdk14

1.7.25-4.module+el8.10.0+90302+23fbc0c1

stax-ex

1.7.7-8.module+el8.10.0+90302+23fbc0c1

velocity

1.7-24.module+el8.10.0+90302+23fbc0c1

xalan-j2

2.7.1-38.module+el8.10.0+90302+23fbc0c1

xerces-j2

2.11.0-34.module+el8.10.0+90302+23fbc0c1

xml-commons-apis

1.4.01-25.module+el8.10.0+90302+23fbc0c1

xml-commons-resolver

1.2-26.module+el8.10.0+90302+23fbc0c1

xmlstreambuffer

1.5.4-8.module+el8.10.0+90302+23fbc0c1

xsom

0-19.20110809svn.module+el8.10.0+90302+23fbc0c1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

CVSS3: 7.5
redhat
около 5 лет назад

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

CVSS3: 7.5
nvd
больше 3 лет назад

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

CVSS3: 7.5
debian
больше 3 лет назад

jackson-databind before 2.13.0 allows a Java StackOverflow exception a ...

CVSS3: 7.5
github
больше 3 лет назад

Deeply nested json in jackson-databind