[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:4847-01 -- Redhat apache-commons-collections, apache-commons-lang, apache-commons-net, bea-stax, glassfish-fastinfoset, glassfish-jaxb, glassfish-jaxb-api, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, jackson-module-jaxb-annotations, jakarta-commons-httpclient, javassist, jss, ldapjdk, pki-core, pki-servlet-engine, python-nss, relaxngDatatype, resteasy, slf4j, stax-ex, tomcatjss, velocity, xalan-j2, xerces-j2, xml-commons-apis, xml-commons-resolver, xmlstreambuffer, xsom-0

ID: oval:org.secpod.oval:def:504689Date: (C)2020-12-23   (M)2024-05-06
Class: PATCHFamily: unix




The Public Key Infrastructure Core contains fundamental packages required by Red Hat Certificate System. Security Fix: * jquery: Cross-site scripting via cross-domain ajax requests * bootstrap: XSS in the data-target attribute * bootstrap: Cross-site Scripting in the collapse data-parent attribute * bootstrap: Cross-site Scripting in the data-container property of tooltip * bootstrap: XSS in the tooltip or popover data-template attribute * jquery: Prototype pollution in object"s prototype leading to denial of service, remote code execution, or property injection * jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method * jquery: Passing HTML containing option elements to manipulation methods could result in untrusted code execution * pki: Dogtag"s python client does not validate certificates * pki-core: Reflected XSS in "path length" constraint field in CA"s Agent page * pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA"s DRM agent page in authorize recovery tab * pki-core: Reflected XSS in getcookies?url= endpoint in CA * pki-core: KRA vulnerable to reflected XSS via the getPk12 page For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 8
Product:
apache-commons-collections
apache-commons-lang
apache-commons-net
bea-stax
glassfish-fastinfoset
glassfish-jaxb
glassfish-jaxb-api
jackson-annotations
jackson-core
jackson-databind
jackson-jaxrs-providers
jackson-module-jaxb-annotations
jakarta-commons-httpclient
javassist
jss
ldapjdk
pki-core
pki-servlet-engine
python-nss
relaxngDatatype
resteasy
slf4j
stax-ex
tomcatjss
velocity
xalan-j2
xerces-j2
xml-commons-apis
xml-commons-resolver
xmlstreambuffer
xsom-0
Reference:
RHSA-2020:4847-01
CVE-2015-9251
CVE-2016-10735
CVE-2018-14040
CVE-2018-14042
CVE-2019-8331
CVE-2019-10146
CVE-2019-10179
CVE-2019-10221
CVE-2019-11358
CVE-2020-1721
CVE-2020-11022
CVE-2020-11023
CVE-2020-15720
CVE-2022-25762
CVE-2020-1935
CVE-2020-25715
CVE-2020-1938
CVE    17
CVE-2022-25762
CVE-2020-1935
CVE-2020-1938
CVE-2020-25715
...
CPE    33
cpe:/a:fasterxml:jackson-annotations
cpe:/a:apache:xalan-j2
cpe:/a:apache:tomcatjss
cpe:/a:redhat:resteasy
...

© SecPod Technologies