Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:7326

Опубликовано: 02 нояб. 2022
Источник: rocky
Оценка: Important

Описание

Important: pki-core security update

The Public Key Infrastructure (PKI) Core contains fundamental packages required by Rocky Enterprise Software Foundation Certificate System.

Security Fix(es):

  • pki-core: access to external entities when parsing XML can lead to XXE (CVE-2022-2414)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-acmenoarch2.el9_0pki-acme-11.0.6-2.el9_0.noarch.rpm
pki-basenoarch2.el9_0pki-base-11.0.6-2.el9_0.noarch.rpm
pki-basenoarch2.el9_0pki-base-11.0.6-2.el9_0.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
redhat
больше 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
nvd
больше 3 лет назад

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

CVSS3: 7.5
debian
больше 3 лет назад

Access to external entities when parsing XML documents can lead to XML ...

rocky
около 3 лет назад

Important: pki-core:10.6 and pki-deps:10.6 security and bug fix update