RHSA-2022:6057MediumCVSS 9.3

Red Hat Security Advisory: .NET Core 3.1 security, bug fix, and enhancement update

Published
August 15, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2022-1650 — eventsource: Exposure of Sensitive Information CVE-2022-34716 — dotnet: External Entity Injection during XML signature verification

🎯 Affected products24

  • Red Hat Enterprise Linux AppStream (v. 8)
  • Red Hat Enterprise Linux CRB (v. 8)
  • aspnetcore-runtime-3.1-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • aspnetcore-targeting-pack-3.1-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-apphost-pack-3.1-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-apphost-pack-3.1-debuginfo-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-apphost-pack-3.1-debuginfo-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • dotnet-hostfxr-3.1-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-hostfxr-3.1-debuginfo-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-hostfxr-3.1-debuginfo-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • dotnet-runtime-3.1-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-runtime-3.1-debuginfo-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-runtime-3.1-debuginfo-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • dotnet-sdk-3.1-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-sdk-3.1-debuginfo-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-sdk-3.1-debuginfo-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • dotnet-sdk-3.1-source-built-artifacts-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • dotnet-targeting-pack-3.1-0:3.1.28-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet-templates-3.1-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet3.1-0:3.1.422-1.el8_6.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet3.1-debuginfo-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet3.1-debuginfo-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • dotnet3.1-debugsource-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • dotnet3.1-debugsource-0:3.1.422-1.el8_6.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (4)