RHSA-2022:8524HighCVSS 7.5

Red Hat Security Advisory: Red Hat Data Grid 8.4.0 security update

Published
November 17, 2022
Last Modified
August 7, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2022-0235 — node-fetch: exposure of sensitive information to an unauthorized actor CVE-2022-23647 — prismjs: improperly escaped output allows a XSS CVE-2022-24823 — netty: world readable temporary file containing sensitive data CVE-2022-25857 — snakeyaml: Denial of Service due to missing nested depth limitation for collections CVE-2022-38749 — snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode CVE-2022-38750 — snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject CVE-2022-38751 — snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match CVE-2022-38752 — snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode

🎯 Affected products1

  • Red Hat Data Grid 8.4.0

✅ Remediation

To install this update, do the following: 1. Download the Data Grid 8.4.0 Server patch from the customer portal[²]. 2. Back up your existing Data Grid installation. You should back up databases, configuration files, and so on. 3. Install the Data Grid 8.4.0 Server patch. 4. Restart Data Grid to ensure the changes take effect. For more information about Data Grid 8.4.0, refer to the 8.4.0 Release Notes[³] Workaround: As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.

🔗 References (13)