Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:7326

Опубликовано: 02 нояб. 2022
Источник: rocky
Оценка: Important

Описание

Important: pki-core security update

The Public Key Infrastructure (PKI) Core contains fundamental packages required by Rocky Enterprise Software Foundation Certificate System.

Security Fix(es):

  • pki-core: access to external entities when parsing XML can lead to XXE (CVE-2022-2414)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-basenoarch2.el9_0pki-base-11.0.6-2.el9_0.noarch.rpm
pki-base-javanoarch2.el9_0pki-base-java-11.0.6-2.el9_0.noarch.rpm
pki-canoarch2.el9_0pki-ca-11.0.6-2.el9_0.noarch.rpm
pki-kranoarch2.el9_0pki-kra-11.0.6-2.el9_0.noarch.rpm
pki-servernoarch2.el9_0pki-server-11.0.6-2.el9_0.noarch.rpm
pki-symkeyx86_642.el9_0pki-symkey-11.0.6-2.el9_0.x86_64.rpm
pki-toolsx86_642.el9_0pki-tools-11.0.6-2.el9_0.x86_64.rpm
python3-pkinoarch2.el9_0python3-pki-11.0.6-2.el9_0.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
redhat
около 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
nvd
почти 3 года назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
debian
почти 3 года назад

Access to external entities when parsing XML documents can lead to XML ...

CVSS3: 7.5
redos
около 2 лет назад

Уязвимость pki-core