RHSA-2023:0713HighCVSS 9.8
Red Hat Security Advisory: Red Hat Data Grid 8.4.1 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2022-36313 — file-type: a malformed MKV file could cause the file type detector to get caught in an infinite loop CVE-2022-37603 — loader-utils: Regular expression denial of service CVE-2022-41881 — codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2022-45047 — mina-sshd: Java unsafe deserialization vulnerability
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2023:0713
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/softwareDetail.html?softwareId=70381&product=data.grid&version=8.4&downloadType=patches
- externalhttps://access.redhat.com/documentation/en-us/red_hat_data_grid/8.4/html-single/red_hat_data_grid_8.4_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135247
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2140597
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2145194
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2153379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2159682
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0713.json