RHSA-2023:0483CriticalCVSS 9.8
Red Hat Security Advisory: Red Hat Fuse 7.11.1.P1 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-36437 — hazelcast: Hazelcast connection caching CVE-2022-46363 — CXF: directory listing / code exfiltration CVE-2022-46364 — CXF: SSRF Vulnerability
🎯 Affected products1
- Red Hat Fuse 7.11.1.P1
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are available from the Fuse 7.11 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.11/
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2023:0483
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=7.11.1
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155681
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2162053
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0483.json