RHSA-2022:7435MediumCVSS 7.5
Red Hat Security Advisory: Logging Subsystem 5.4.8 - Red Hat OpenShift security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2022-32149 — golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2022:7435
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064698
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135247
- externalhttps://issues.redhat.com/browse/LOG-3250
- externalhttps://issues.redhat.com/browse/LOG-3252
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_7435.json