RHSA-2023:0713HighCVSS 9.8

Red Hat Security Advisory: Red Hat Data Grid 8.4.1 security update

Published
February 9, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2022-36313 — file-type: a malformed MKV file could cause the file type detector to get caught in an infinite loop CVE-2022-37603 — loader-utils: Regular expression denial of service CVE-2022-41881 — codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2022-45047 — mina-sshd: Java unsafe deserialization vulnerability

🎯 Affected products1

  • Red Hat Data Grid 8.4.1

✅ Remediation

To install this update, do the following: 1. Download the Data Grid 8.4.1 Server patch from the customer portal[²]. 2. Back up your existing Data Grid installation. You should back up databases, configuration files, and so on. 3. Install the Data Grid 8.4.1 Server patch. 4. Restart Data Grid to ensure the changes take effect. For more information about Data Grid 8.4.1, refer to the 8.4.1 Release Notes[³] Workaround: From the maintainer: For Apache MINA SSHD <= 2.9.1, do not use org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider to generate and later load your server's host key. Use separately generated host key files, for instance in OpenSSH format, and load them via a org.apache.sshd.common.keyprovider.FileKeyPairProvider instead. Or use a custom implementation instead of SimpleGeneratorHostKeyProvider that uses the OpenSSH format for storing and loading the host key (via classes OpenSSHKeyPairResourceWriter and OpenSSHKeyPairResourceParser).

🔗 References (11)