Описание
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
A flaw was found in pki-core. Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
Меры по смягчению последствий
There is no known mitigation for this issue, please update the affected package as soon as possible.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Certificate System 10 | pki-core | Affected | ||
Red Hat Enterprise Linux 6 | pki-core | Out of support scope | ||
Red Hat Certificate System 9.7 | pki-core | Fixed | RHSA-2022:8915 | 12.12.2022 |
Red Hat Enterprise Linux 7 | pki-core | Fixed | RHSA-2022:8799 | 06.12.2022 |
Red Hat Enterprise Linux 8 | pki-core | Fixed | RHSA-2022:7470 | 08.11.2022 |
Red Hat Enterprise Linux 8.2 Advanced Update Support | pki-core | Fixed | RHSA-2023:1747 | 12.04.2023 |
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | pki-core | Fixed | RHSA-2023:1747 | 12.04.2023 |
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | pki-core | Fixed | RHSA-2023:1747 | 12.04.2023 |
Red Hat Enterprise Linux 8.4 Extended Update Support | pki-core | Fixed | RHSA-2023:1966 | 25.04.2023 |
Red Hat Enterprise Linux 8.6 Extended Update Support | pki-core | Fixed | RHSA-2023:3394 | 31.05.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
Access to external entities when parsing XML documents can lead to XML ...
Important: pki-core:10.6 and pki-deps:10.6 security and bug fix update
EPSS
7.5 High
CVSS3