elsa-2022-7470

oracle_linux
Description

apache-commons-collections apache-commons-net [3.6-3] - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild [3.6-2] - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild [3.6-1] - Update to upstream version 3.6 jss [4.9.4-1] - Rebase to JSS 4.9.4 - Bug 2013674 - JSS cannot be properly initialized after using another NSS-backed security provider ldapjdk [4.23.0-1] - Rebase to LDAP SDK 4.23.0 [4.23.0-0.1] - Rebase to LDAP SDK 4.23.0-alpha1 pki-core [10.12.0-4.0.1] - Remove upstream reference. [10.12.0-4] - Bug 2107334 - CVE-2022-2414 access to external entities when parsing XML can lead to XXE - Rename packages to idm-pki [10.12.0-3] - ExcludeArch i686 as md2man not available in RHEL 8.7 [10.12.0-2] - Bug 2027470 - pki-healthcheck ClonesConnectivyAndDataCheck fails [10.12.0-0.1] - Rebase to PKI 10.12.0 - Bug 1904112 - pki fails to start if empty dir /var/lib/pki/pki-tomcat/kra exists - Bug 1984455 - [RFE] Date Format on the TPS Agent Page - Bug 1980378 - keyctl_search: Required key not available message when running ipa-healthcheck - Bug 2004084 - Reinstall of the same ipa-replica fails with RuntimeError: CA configuration failed. - Bug 2006070 - Upgrades incorrectly add secret attribute to connectors pki-servlet-engine [1:9.0.50-1] - Update to JWS 5.6.1 distribution - Resolves: rhbz#2057162 Rebase pki-servlet-engine to 9.0.50 resteasy [3.0.26-6] - CVE-2020-1695: Improper validation of response header in MediaTypeHeaderDelegate.java class Resolves: rh-bz#1845548 tomcatjss [7.7.1-1] - Rebase to TomcatJSS 7.7.1 xml-commons-apis [1.4.01-25] - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild [1.4.01-24] - Elimitate race condition when injecting JAR manifest - Resolves: rhbz#1495249 [1.4.01-23] - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild [1.4.01-22] - Update to current packaging guidelines [1.4.01-21] - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild [1.4.01-20] - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild [1.4.01-19] - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild [1.4.01-18] - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild [1.4.01-17] - Dont generate duplicate Maven metadata [1.4.01-16] - Use .mfiles generated during build [1.4.01-15] - Use Requires: java-headless rebuild (#1067528) [1.4.01-14] - Fix FTBFS. [1.4.01-13] - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild [1.4.01-12] - Update manifest to match Eclipse version (Resolved: rhbz#964039). [1.4.01-11] - Add Require-Bundle: system.bundle to manifest - Resolves: rhbz#917659 [1.4.01-10] - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild [1.4.01-9] - Add additional maven depmap [1.4.01-8] - Remove osgi(system.bundle) requirement from manifest [1.4.01-7] - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild [1.4.01-6] - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild [1.4.01-5] - Add missing packages to manifest - javax.xml.stream, javax.xml.stream.events, javax.xml.stream.util, javax.xml.transform.stax (bug #743360) [1.4.01-4] - Add maven metadata - Few guidelines tweaks (buildroot, clean, defattr) - Versionless jars javadocs [1.4.01-3] - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild [1.4.01-2] - Fix FTBFS and rpmlint warnings. - Dont package javadoc in manual package. [0:1.4.01-1] - Update to 1.4.01.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2022-2414"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "apache-commons-collections\napache-commons-net\n[3.6-3]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild\n\n[3.6-2]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild\n\n[3.6-1]\n- Update to upstream version 3.6\n\njss\n[4.9.4-1]\n- Rebase to JSS 4.9.4\n- Bug 2013674 - JSS cannot be properly initialized after using another NSS-backed security provider\n\nldapjdk\n[4.23.0-1]\n- Rebase to LDAP SDK 4.23.0\n\n[4.23.0-0.1]\n- Rebase to LDAP SDK 4.23.0-alpha1\n\npki-core\n[10.12.0-4.0.1]\n- Remove upstream reference.\n\n[10.12.0-4]\n- Bug 2107334 - CVE-2022-2414 access to external entities when parsing XML can lead to XXE\n- Rename packages to idm-pki\n\n[10.12.0-3]\n- ExcludeArch i686 as md2man not available in RHEL 8.7\n\n[10.12.0-2]\n- Bug 2027470 - pki-healthcheck ClonesConnectivyAndDataCheck fails\n\n[10.12.0-0.1]\n- Rebase to PKI 10.12.0\n- Bug 1904112 - pki fails to start if empty dir /var/lib/pki/pki-tomcat/kra exists\n- Bug 1984455 - [RFE] Date Format on the TPS Agent Page\n- Bug 1980378 - keyctl_search: Required key not available message when running ipa-healthcheck\n- Bug 2004084 - Reinstall of the same ipa-replica fails with RuntimeError: CA configuration failed.\n- Bug 2006070 - Upgrades incorrectly add secret attribute to connectors\n\n\npki-servlet-engine\n[1:9.0.50-1]\n- Update to JWS 5.6.1 distribution\n- Resolves: rhbz#2057162 Rebase pki-servlet-engine to 9.0.50\n\nresteasy\n[3.0.26-6]\n- CVE-2020-1695: Improper validation of response header in MediaTypeHeaderDelegate.java class\n  Resolves: rh-bz#1845548\n\ntomcatjss\n[7.7.1-1]\n- Rebase to TomcatJSS 7.7.1\n\nxml-commons-apis\n[1.4.01-25]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild\n\n[1.4.01-24]\n- Elimitate race condition when injecting JAR manifest\n- Resolves: rhbz#1495249\n\n[1.4.01-23]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild\n\n[1.4.01-22]\n- Update to current packaging guidelines\n\n[1.4.01-21]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild\n\n[1.4.01-20]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild\n\n[1.4.01-19]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild\n\n[1.4.01-18]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild\n\n[1.4.01-17]\n- Dont generate duplicate Maven metadata\n\n[1.4.01-16]\n- Use .mfiles generated during build\n\n[1.4.01-15]\n- Use Requires: java-headless rebuild (#1067528)\n\n[1.4.01-14]\n- Fix FTBFS.\n\n[1.4.01-13]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild\n\n[1.4.01-12]\n- Update manifest to match Eclipse version (Resolved: rhbz#964039).\n\n[1.4.01-11]\n- Add Require-Bundle: system.bundle to manifest\n- Resolves: rhbz#917659\n\n[1.4.01-10]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild\n\n[1.4.01-9]\n- Add additional maven depmap\n\n[1.4.01-8]\n- Remove osgi(system.bundle) requirement from manifest\n\n[1.4.01-7]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild\n\n[1.4.01-6]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild\n\n[1.4.01-5]\n- Add missing packages to manifest - javax.xml.stream, javax.xml.stream.events,\n  javax.xml.stream.util, javax.xml.transform.stax (bug #743360)\n\n[1.4.01-4]\n- Add maven metadata\n- Few guidelines tweaks (buildroot, clean, defattr)\n- Versionless jars  javadocs\n\n[1.4.01-3]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild\n\n[1.4.01-2]\n- Fix FTBFS and rpmlint warnings.\n- Dont package javadoc in manual package.\n\n[0:1.4.01-1]\n- Update to 1.4.01.",
  "id": "ELSA-2022-7470",
  "ovalId": "oval:com.oracle.elsa:def:20227470",
  "source": "oracle_linux",
  "title": "ELSA-2022-7470:  pki-core:10.6 and pki-deps:10.6 security and bug fix update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2022-7470.html"
}
View JSON API Download JSON