Lucene search

K
almalinuxAlmaLinuxALSA-2024:3061
HistoryMay 22, 2024 - 12:00 a.m.

Moderate: pki-core:10.6 and pki-deps:10.6 security update

2024-05-2200:00:00
errata.almalinux.org
2
almalinux
pki-core
pki-deps
security update
jackson-databind
denial of service

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.1%

The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System.

Security Fix(es):

  • jackson-databind: denial of service via a large depth of nested objects (CVE-2020-36518)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

OSVersionArchitecturePackageVersionFilename
almalinux8noarchxmlstreambuffer< 1.5.4-8.module_el8.5.0+2577+9e95fe00Packages/xmlstreambuffer-1.5.4-8.module_el8.5.0+2577+9e95fe00.noarch.rpm
almalinux8noarchjakarta-commons-httpclient< 3.1-28.module_el8.5.0+2577+9e95fe00Packages/jakarta-commons-httpclient-3.1-28.module_el8.5.0+2577+9e95fe00.noarch.rpm
almalinux8noarchrelaxngdatatype< 2011.1-7.module_el8.5.0+2577+9e95fe00Packages/relaxngDatatype-2011.1-7.module_el8.5.0+2577+9e95fe00.noarch.rpm
almalinux8noarchfasterxml-oss-parent< 49-1.module_el8.10.0+3791+e0637953fasterxml-oss-parent-49-1.module_el8.10.0+3791+e0637953.noarch.rpm
almalinux8noarchapache-commons-collections< 3.2.2-10.module_el8.5.0+2577+9e95fe00Packages/apache-commons-collections-3.2.2-10.module_el8.5.0+2577+9e95fe00.noarch.rpm
almalinux8noarchjavassist< 3.18.1-8.module_el8.5.0+2577+9e95fe00Packages/javassist-3.18.1-8.module_el8.5.0+2577+9e95fe00.noarch.rpm
almalinux8noarchxml-commons-resolver< 1.2-26.module_el8.5.0+2577+9e95fe00Packages/xml-commons-resolver-1.2-26.module_el8.5.0+2577+9e95fe00.noarch.rpm
almalinux8noarchglassfish-jaxb-core< 2.2.11-12.module_el8.10.0+3791+e0637953glassfish-jaxb-core-2.2.11-12.module_el8.10.0+3791+e0637953.noarch.rpm
almalinux8noarchpki-servlet-engine< 9.0.62-1.module_el8.10.0+3791+e0637953pki-servlet-engine-9.0.62-1.module_el8.10.0+3791+e0637953.noarch.rpm
almalinux8noarchxerces-j2< 2.11.0-34.module_el8.5.0+2577+9e95fe00Packages/xerces-j2-2.11.0-34.module_el8.5.0+2577+9e95fe00.noarch.rpm
Rows per page:
1-10 of 341

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.1%