Red Hat Security Advisory: parfait:0.5 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-4104 — log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender CVE-2022-23302 — log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink CVE-2022-23305 — log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender CVE-2022-23307 — log4j: Unsafe deserialization flaw in Chainsaw log viewer
🎯 Affected products23
- Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- parfait-0:0.5.4-4.module+el8.1.0+14000+df5fdac7.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- parfait-0:0.5.4-4.module+el8.1.0+14000+df5fdac7.src (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- parfait-examples-0:0.5.4-4.module+el8.1.0+14000+df5fdac7.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- parfait-javadoc-0:0.5.4-4.module+el8.1.0+14000+df5fdac7.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- pcp-parfait-agent-0:0.5.4-4.module+el8.1.0+14000+df5fdac7.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- si-units-0:0.6.5-2.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- si-units-0:0.6.5-2.module+el8+2463+615f6896.src (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- si-units-javadoc-0:0.6.5-2.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- unit-api-0:1.0-5.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- unit-api-0:1.0-5.module+el8+2463+615f6896.src (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- unit-api-javadoc-0:1.0-5.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-lib-0:1.0.1-6.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-lib-0:1.0.1-6.module+el8+2463+615f6896.src (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-lib-javadoc-0:1.0.1-6.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-parent-0:1.0.3-3.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-parent-0:1.0.3-3.module+el8+2463+615f6896.src (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-se-0:1.0.4-3.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-se-0:1.0.4-3.module+el8+2463+615f6896.src (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-se-javadoc-0:1.0.4-3.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-systems-0:0.7-1.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-systems-0:0.7-1.module+el8+2463+615f6896.src (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- uom-systems-javadoc-0:0.7-1.module+el8+2463+615f6896.noarch (parfait:0.5) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JMSAppender in the Log4j configuration if it is used - Remove the JMSAppender class from the classpath. For example: ``` zip -q -d log4j-*.jar org/apache/log4j/net/JMSAppender.class ``` - Restrict access for the OS user on the platform running the application to prevent modifying the Log4j configuration by the attacker. Workaround: These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JMSSink in the Log4j configuration if it is used - Remove the JMSSink class from the server's jar files. For example: ``` zip -q -d log4j-*.jar org/apache/log4j/net/JMSSink.class ``` - Restrict access for the OS user on the platform running the application to prevent modifying the Log4j configuration by the attacker. Workaround: These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JDBCAppender in the Log4j configuration if it is used - Remove the JDBCAppender class from the server's jar files. For example: ``` zip -q -d log4j-*.jar org/apache/log4j/jdbc/JDBCAppender.class ``` Workaround: These are the mitigations available for this flaw for log4j 1.x: - Avoid using Chainsaw to view logs, and instead use some other utility, especially if there is a log view available within the product itself. - Remove the Chainsaw classes from the log4j jar files. For example: ``` zip -q -d log4j-*.jar org/apache/log4j/chainsaw/* ``` (log4j jars may be nested in zip archives within product)
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2022:0294
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2021-009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031667
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041967
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0294.json