VARIoT IoT vulnerabilities database
| VAR-202104-1941 | CVE-2021-27460 | Rockwell Automation Made FactoryTalk AssetCentre Multiple vulnerabilities in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk AssetCentre main server and all agent machines. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets
| VAR-202104-1938 | CVE-2021-27470 | Rockwell Automation Made FactoryTalk AssetCentre Multiple vulnerabilities in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets. Provides centralized tools for securing, managing, versioning, tracking and reporting automation-related asset information across the plant FactoryTalk AssetCentre verifies serialized data A security vulnerability exists that allows remote, unauthenticated attackers to The center executes arbitrary commands
| VAR-202104-1942 | CVE-2021-27476 | Rockwell Automation Made FactoryTalk AssetCentre Multiple vulnerabilities in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets
| VAR-202104-1943 | CVE-2021-27474 | Rockwell Automation Made FactoryTalk AssetCentre Multiple vulnerabilities in |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets. Provides centralized tools to secure, manage, version control, track and report automation-related asset information across the factory FactoryTalk AssetCentre has a security vulnerability that stems from not properly restricting all functions related to IIS Remote Services Attackers This vulnerability could be exploited to modify sensitive data in FactoryTalk Asset Center
| VAR-202104-1937 | CVE-2021-27462 | Rockwell Automation Made FactoryTalk AssetCentre Multiple vulnerabilities in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets
| VAR-202104-1945 | CVE-2021-27468 | Rockwell Automation Made FactoryTalk AssetCentre Multiple vulnerabilities in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets.
Rockwell Automation FactoryTalk AssetCentre has a SQL injection vulnerability. Provides a centralized tool for securing, managing, versioning, tracking and reporting automation-related asset information across a factory
| VAR-202104-1944 | CVE-2021-27472 | Rockwell Automation FactoryTalk AssetCentre SQL Injection Vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets.
Rockwell Automation FactoryTalk AssetCentre has a SQL injection vulnerability
| VAR-202104-1940 | CVE-2021-27464 | Rockwell Automation Made FactoryTalk AssetCentre Multiple vulnerabilities in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. Rockwell Automation Provided by the company FactoryTalk AssetCentre The following multiple vulnerabilities exist in. * Deserialize untrusted data (CWE-502) - CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 , CVE-2021-27460 ‥ * Use of potentially dangerous functions (CWE-676) - CVE-2021-27474 ‥ * OS Command injection (CWE-78) - CVE-2021-27476 ‥ * SQL injection (CWE-89) - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464The expected impact depends on each vulnerability, but it may be affected as follows. * Arbitrary command executed by an unauthenticated remote third party - CVE-2021-27476 , CVE-2021-27470 , CVE-2021-27466 , CVE-2021-27462 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Confidential data is changed - CVE-2021-27474 ‥ * Any by an unauthenticated remote third party SQL The statement is executed - CVE-2021-27472 , CVE-2021-27468 , CVE-2021-27464 ‥ * By an unauthenticated remote third party FactoryTalk AssetCentre Accessed to main server and all agent machines - CVE-2021-27460. Rockwell Automation FactoryTalk AssetCentre is an asset management software tool launched by Rockwell Automation, USA, which can be used by manufacturers and industrial enterprises for centralized management of controllers and other automation-related assets.
Rockwell Automation FactoryTalk AssetCentre has a SQL injection vulnerability
| VAR-202104-1920 | CVE-2020-9146 | Huawei Vulnerability regarding lack of release of resources after valid lifetime on smartphones |
CVSS V2: 1.9 CVSS V3: 5.5 Severity: MEDIUM |
A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to cause memory leakage and doS attacks by carefully constructing attack scenarios. Huawei Smartphones contain a vulnerability regarding the lack of resource release after a valid lifetime.Denial of service (DoS) It may be put into a state. Huawei Emui is an Android-based mobile operating system developed by China's Huawei (Huawei)
| VAR-202104-1919 | CVE-2020-9147 | Huawei Classic buffer overflow vulnerability in smartphones |
CVSS V2: 4.4 CVSS V3: 7.8 Severity: HIGH |
A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit this vulnerability by carefully constructing attack scenarios to cause out-of-bounds read. Huawei A classic buffer overflow vulnerability exists in smartphones.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Huawei Emui is an Android-based mobile operating system developed by China's Huawei (Huawei)
| VAR-202104-1918 | CVE-2020-9148 | Huawei Vulnerability in smartphones |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
An application bypass mechanism vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to delete user SMS messages. Huawei There are unspecified vulnerabilities in smartphones.Information may be tampered with
| VAR-202104-1917 | CVE-2020-9149 | Huawei Vulnerability in smartphones |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
An application error verification vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to modify and delete user SMS messages. Huawei There are unspecified vulnerabilities in smartphones.Information may be tampered with
| VAR-202104-1628 | CVE-2021-29083 | Synology DiskStation Manager In OS Command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 7.2 Severity: HIGH |
Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter. Synology DiskStation Manager (DSM) Has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Synology DiskStation Manager (DSM) is an operating system for network storage servers (NAS) developed by Synology, Taiwan. The operating system can manage data, documents, photos, music and other information
| VAR-202104-1582 | CVE-2021-26581 | HPE Superdome Flex server Vulnerability in |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following software update to resolve the vulnerability in HPE Superdome Flex Server: Superdome Flex Server Firmware 3.30.142 or later
| VAR-202103-1816 | No CVE | (0Day) D-Link DIR-882 HNAP Stack-based Buffer Overflow Remote Code Execution Vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-882 routers. Authentication is not required to exploit this vulnerability.The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.
| VAR-202104-0334 | CVE-2021-22876 | curl Information Disclosure Vulnerability |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. curl Contains an information disclosure vulnerability.Information may be obtained. This could lead to exposure of the credentials to the server to which requests were redirected. (CVE-2021-22876)
A vulnerability was found in curl where a flaw in the option parser for sending NEW_ENV variables libcurl can pass uninitialized data from a stack-based buffer to the server. This issue leads to potentially revealing sensitive internal information to the server using a clear-text network protocol. The highest threat from this vulnerability is to confidentiality. (CVE-2021-22898). Bugs fixed (https://bugzilla.redhat.com/):
2030932 - CVE-2021-44228 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
5. 8) - aarch64, ppc64le, s390x, x86_64
3. Description:
The curl packages provide the libcurl library and the curl utility for
downloading files from servers using various protocols, including HTTP,
FTP, and LDAP. Bugs fixed (https://bugzilla.redhat.com/):
1941964 - CVE-2021-22876 curl: Leak of authentication credentials in URL via automatic Referer
1947493 - Why there is a difference between curl --head output on the RHEL7 and RHEL8. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP8 security update
Advisory ID: RHSA-2021:2472-01
Product: Red Hat JBoss Core Services
Advisory URL: https://access.redhat.com/errata/RHSA-2021:2472
Issue date: 2021-06-17
CVE Names: CVE-2020-8169 CVE-2020-8284 CVE-2020-8285
CVE-2020-8286 CVE-2021-22876 CVE-2021-22890
CVE-2021-22901 CVE-2021-31618
=====================================================================
1. Summary:
Updated packages that provide Red Hat JBoss Core Services Pack Apache
Server 2.4.37 and fix several bugs, and add various enhancements are now
available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat JBoss Core Services on RHEL 7 Server - noarch, ppc64, x86_64
Red Hat JBoss Core Services on RHEL 8 - noarch, x86_64
3. Description:
This release adds the new Apache HTTP Server 2.4.37 Service Pack 8 packages
that are part of the JBoss Core Services offering.
This release serves as a replacement for Red Hat JBoss Core Services Pack
Apache Server 2.4.37 Service Pack 7 and includes bug fixes and
enhancements. Refer to the Release Notes for information on the most
significant bug fixes and enhancements included in this release.
Security Fix(es):
* curl: Use-after-free in TLS session handling when using OpenSSL TLS
backend (CVE-2021-22901)
* httpd: NULL pointer dereference on specially crafted HTTP/2 request
(CVE-2021-31618)
* libcurl: partial password leak over DNS on HTTP redirect (CVE-2020-8169)
* curl: FTP PASV command response can cause curl to connect to arbitrary
host (CVE-2020-8284)
* curl: Malicious FTP server can trigger stack overflow when
CURLOPT_CHUNK_BGN_FUNCTION is used (CVE-2020-8285)
* curl: Inferior OCSP verification (CVE-2020-8286)
* curl: Leak of authentication credentials in URL via automatic Referer
(CVE-2021-22876)
* curl: TLS 1.3 session ticket mix-up with HTTPS proxy host
(CVE-2021-22890)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the updated packages, the httpd daemon will be restarted
automatically. Applications using the APR libraries, such as httpd, must be
restarted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1847916 - CVE-2020-8169 libcurl: partial password leak over DNS on HTTP redirect
1902667 - CVE-2020-8284 curl: FTP PASV command response can cause curl to connect to arbitrary host
1902687 - CVE-2020-8285 curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used
1906096 - CVE-2020-8286 curl: Inferior OCSP verification
1941964 - CVE-2021-22876 curl: Leak of authentication credentials in URL via automatic Referer
1941965 - CVE-2021-22890 curl: TLS 1.3 session ticket mix-up with HTTPS proxy host
1963146 - CVE-2021-22901 curl: Use-after-free in TLS session handling when using OpenSSL TLS backend
1968013 - CVE-2021-31618 httpd: NULL pointer dereference on specially crafted HTTP/2 request
6. Package List:
Red Hat JBoss Core Services on RHEL 7 Server:
Source:
jbcs-httpd24-1-18.jbcs.el7.src.rpm
jbcs-httpd24-apr-1.6.3-105.jbcs.el7.src.rpm
jbcs-httpd24-apr-util-1.6.1-82.jbcs.el7.src.rpm
jbcs-httpd24-curl-7.77.0-2.jbcs.el7.src.rpm
jbcs-httpd24-httpd-2.4.37-74.jbcs.el7.src.rpm
jbcs-httpd24-jansson-2.11-55.jbcs.el7.src.rpm
jbcs-httpd24-mod_cluster-native-1.3.16-5.Final_redhat_2.jbcs.el7.src.rpm
jbcs-httpd24-mod_http2-1.15.7-17.jbcs.el7.src.rpm
jbcs-httpd24-mod_jk-1.2.48-16.redhat_1.jbcs.el7.src.rpm
jbcs-httpd24-mod_md-2.0.8-36.jbcs.el7.src.rpm
jbcs-httpd24-mod_security-2.9.2-63.GA.jbcs.el7.src.rpm
noarch:
jbcs-httpd24-httpd-manual-2.4.37-74.jbcs.el7.noarch.rpm
ppc64:
jbcs-httpd24-1-18.jbcs.el7.ppc64.rpm
jbcs-httpd24-curl-7.77.0-2.jbcs.el7.ppc64.rpm
jbcs-httpd24-curl-debuginfo-7.77.0-2.jbcs.el7.ppc64.rpm
jbcs-httpd24-jansson-2.11-55.jbcs.el7.ppc64.rpm
jbcs-httpd24-jansson-debuginfo-2.11-55.jbcs.el7.ppc64.rpm
jbcs-httpd24-jansson-devel-2.11-55.jbcs.el7.ppc64.rpm
jbcs-httpd24-libcurl-7.77.0-2.jbcs.el7.ppc64.rpm
jbcs-httpd24-libcurl-devel-7.77.0-2.jbcs.el7.ppc64.rpm
jbcs-httpd24-mod_http2-1.15.7-17.jbcs.el7.ppc64.rpm
jbcs-httpd24-mod_http2-debuginfo-1.15.7-17.jbcs.el7.ppc64.rpm
jbcs-httpd24-mod_md-2.0.8-36.jbcs.el7.ppc64.rpm
jbcs-httpd24-mod_md-debuginfo-2.0.8-36.jbcs.el7.ppc64.rpm
jbcs-httpd24-runtime-1-18.jbcs.el7.ppc64.rpm
x86_64:
jbcs-httpd24-1-18.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-1.6.3-105.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-debuginfo-1.6.3-105.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-devel-1.6.3-105.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-debuginfo-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-devel-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-ldap-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-mysql-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-nss-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-odbc-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-openssl-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-1.6.1-82.jbcs.el7.x86_64.rpm
jbcs-httpd24-curl-7.77.0-2.jbcs.el7.x86_64.rpm
jbcs-httpd24-curl-debuginfo-7.77.0-2.jbcs.el7.x86_64.rpm
jbcs-httpd24-httpd-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-httpd-debuginfo-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-httpd-devel-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-httpd-selinux-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-httpd-tools-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-jansson-2.11-55.jbcs.el7.x86_64.rpm
jbcs-httpd24-jansson-debuginfo-2.11-55.jbcs.el7.x86_64.rpm
jbcs-httpd24-jansson-devel-2.11-55.jbcs.el7.x86_64.rpm
jbcs-httpd24-libcurl-7.77.0-2.jbcs.el7.x86_64.rpm
jbcs-httpd24-libcurl-devel-7.77.0-2.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_cluster-native-1.3.16-5.Final_redhat_2.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_cluster-native-debuginfo-1.3.16-5.Final_redhat_2.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_http2-1.15.7-17.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_http2-debuginfo-1.15.7-17.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-1.2.48-16.redhat_1.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_jk-debuginfo-1.2.48-16.redhat_1.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_jk-manual-1.2.48-16.redhat_1.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_ldap-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_md-2.0.8-36.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_md-debuginfo-2.0.8-36.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_proxy_html-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_security-2.9.2-63.GA.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_security-debuginfo-2.9.2-63.GA.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_session-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-mod_ssl-2.4.37-74.jbcs.el7.x86_64.rpm
jbcs-httpd24-runtime-1-18.jbcs.el7.x86_64.rpm
Red Hat JBoss Core Services on RHEL 8:
Source:
jbcs-httpd24-1-18.el8jbcs.src.rpm
jbcs-httpd24-apr-1.6.3-105.el8jbcs.src.rpm
jbcs-httpd24-apr-util-1.6.1-82.el8jbcs.src.rpm
jbcs-httpd24-brotli-1.0.6-40.el8jbcs.src.rpm
jbcs-httpd24-curl-7.77.0-2.el8jbcs.src.rpm
jbcs-httpd24-httpd-2.4.37-74.el8jbcs.src.rpm
jbcs-httpd24-jansson-2.11-55.el8jbcs.src.rpm
jbcs-httpd24-mod_cluster-native-1.3.16-5.Final_redhat_2.el8jbcs.src.rpm
jbcs-httpd24-mod_http2-1.15.7-17.el8jbcs.src.rpm
jbcs-httpd24-mod_jk-1.2.48-16.redhat_1.el8jbcs.src.rpm
jbcs-httpd24-mod_md-2.0.8-36.el8jbcs.src.rpm
jbcs-httpd24-mod_security-2.9.2-63.GA.el8jbcs.src.rpm
jbcs-httpd24-nghttp2-1.39.2-37.el8jbcs.src.rpm
jbcs-httpd24-openssl-1.1.1g-6.el8jbcs.src.rpm
jbcs-httpd24-openssl-chil-1.0.0-5.el8jbcs.src.rpm
jbcs-httpd24-openssl-pkcs11-0.4.10-20.el8jbcs.src.rpm
noarch:
jbcs-httpd24-httpd-manual-2.4.37-74.el8jbcs.noarch.rpm
x86_64:
jbcs-httpd24-1-18.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-1.6.3-105.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-debuginfo-1.6.3-105.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-devel-1.6.3-105.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-devel-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-ldap-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-ldap-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-mysql-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-mysql-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-nss-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-nss-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-odbc-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-odbc-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-openssl-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-openssl-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-debuginfo-1.6.1-82.el8jbcs.x86_64.rpm
jbcs-httpd24-brotli-1.0.6-40.el8jbcs.x86_64.rpm
jbcs-httpd24-brotli-debuginfo-1.0.6-40.el8jbcs.x86_64.rpm
jbcs-httpd24-brotli-devel-1.0.6-40.el8jbcs.x86_64.rpm
jbcs-httpd24-curl-7.77.0-2.el8jbcs.x86_64.rpm
jbcs-httpd24-curl-debuginfo-7.77.0-2.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-devel-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-selinux-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-tools-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-tools-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-jansson-2.11-55.el8jbcs.x86_64.rpm
jbcs-httpd24-jansson-debuginfo-2.11-55.el8jbcs.x86_64.rpm
jbcs-httpd24-jansson-devel-2.11-55.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-7.77.0-2.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-debuginfo-7.77.0-2.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-devel-7.77.0-2.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_cluster-native-1.3.16-5.Final_redhat_2.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_cluster-native-debuginfo-1.3.16-5.Final_redhat_2.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-1.15.7-17.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-debuginfo-1.15.7-17.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-1.2.48-16.redhat_1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-debuginfo-1.2.48-16.redhat_1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-manual-1.2.48-16.redhat_1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ldap-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ldap-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_md-2.0.8-36.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_md-debuginfo-2.0.8-36.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_html-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_html-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_security-2.9.2-63.GA.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_security-debuginfo-2.9.2-63.GA.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_session-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_session-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ssl-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ssl-debuginfo-2.4.37-74.el8jbcs.x86_64.rpm
jbcs-httpd24-nghttp2-1.39.2-37.el8jbcs.x86_64.rpm
jbcs-httpd24-nghttp2-debuginfo-1.39.2-37.el8jbcs.x86_64.rpm
jbcs-httpd24-nghttp2-devel-1.39.2-37.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-1.1.1g-6.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-chil-1.0.0-5.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-chil-debuginfo-1.0.0-5.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-debuginfo-1.1.1g-6.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-devel-1.1.1g-6.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-libs-1.1.1g-6.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-libs-debuginfo-1.1.1g-6.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-perl-1.1.1g-6.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-pkcs11-0.4.10-20.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-pkcs11-debuginfo-0.4.10-20.el8jbcs.x86_64.rpm
jbcs-httpd24-openssl-static-1.1.1g-6.el8jbcs.x86_64.rpm
jbcs-httpd24-runtime-1-18.el8jbcs.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2020-8169
https://access.redhat.com/security/cve/CVE-2020-8284
https://access.redhat.com/security/cve/CVE-2020-8285
https://access.redhat.com/security/cve/CVE-2020-8286
https://access.redhat.com/security/cve/CVE-2021-22876
https://access.redhat.com/security/cve/CVE-2021-22890
https://access.redhat.com/security/cve/CVE-2021-22901
https://access.redhat.com/security/cve/CVE-2021-31618
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYMs2wNzjgjWX9erEAQiuqA//Wj88udaE82j3T1g70vO9Zf9s0Ym+xAWi
SmIBQfiNIh9WRy9Jp6DqIxPtG7HQ+++VwXU2lx9LjXuicsQnmKRjdQtvYtqbCzbq
uOrxFeLSK1AeI0ic9wo5a7JHxyzcg9yTxCIw8QtTzqpJjJHWTBK/xtiYp9V6A2xF
NaXdlAyCRfje+0+EygZGBdX5UD6cr8vTLPtVmp2t+NfvyB7YQaHwSMi7ZzKvmN61
ZLj5++qEWde9k8zovupYAAe9suIwzaL4bdgbwdSyFYH/CDA1E9oyo22inzO4iaka
ixwuhI8rnToaVLNyn7p/Ra585stBQ1GUE27dJBvlabYa35gdoVVy+e0mRsQ/pS3R
vE48A9yOLhSaof8l2ZDQRuhr6KBFFEvdln7TcftIdQG7/iTVo0R03AxigGGn1bSv
HQ911R6wcPAU300VfeIo5btkbJCPBHoovYCBJYBVlF5wjQ7RCWlr9VrX/wqMun68
8IrfPX8j4PIwUvxPygqIFUjg0xZHWiVN8H6tNeJKD8kHfv/4vCIOo9ZWxFI5VFV/
/2pqWtm5tnf3yfqFn8Z6OrkaQFR8q0jg0d2VLS4AmKC4joLTXvBZVKLEfLF+HGlO
QnEYJ2EhDWHSU+ZViI/anzTRnN5tBxNxqsPn7rfTXLmxxwkUH9hgaCzVMG5MXYOZ
lIrXPlR2tmY=
=6HuS
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. Description:
Red Hat Advanced Cluster Management for Kubernetes 2.2.10 images
Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability engineers face as they work across a range of public and
private cloud environments.
Clusters and applications are all visible and managed from a single console
— with security policy built in. See the following Release Notes documentation, which
will be updated shortly for this release, for additional details about this
release:
https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.2/html/release_notes/
Security fixes:
* CVE-2021-3795 semver-regex: inefficient regular expression complexity
* CVE-2021-23440 nodejs-set-value: type confusion allows bypass of
CVE-2019-10747
Related bugs:
* RHACM 2.2.10 images (Bugzilla #2013652)
3. Bugs fixed (https://bugzilla.redhat.com/):
2004944 - CVE-2021-23440 nodejs-set-value: type confusion allows bypass of CVE-2019-10747
2006009 - CVE-2021-3795 semver-regex: inefficient regular expression complexity
2013652 - RHACM 2.2.10 images
5.
Red Hat OpenShift Container Storage is highly scalable, production-grade
persistent storage for stateful applications running in the Red Hat
OpenShift Container Platform. In addition to persistent storage, Red Hat
OpenShift Container Storage provides a multicloud data management service
with an S3 compatible API.
Bug Fix(es):
* Previously, when the namespace store target was deleted, no alert was
sent to the namespace bucket because of an issue in calculating the
namespace bucket health. With this update, the issue in calculating the
namespace bucket health is fixed and alerts are triggered as expected.
(BZ#1993873)
* Previously, the Multicloud Object Gateway (MCG) components performed
slowly and there was a lot of pressure on the MCG components due to
non-optimized database queries. With this update the non-optimized
database queries are fixed which reduces the compute resources and time
taken for queries. Bugs fixed (https://bugzilla.redhat.com/):
1993873 - [4.8.z clone] Alert NooBaaNamespaceBucketErrorState is not triggered when namespacestore's target bucket is deleted
2006958 - CVE-2020-26301 nodejs-ssh2: Command injection by calling vulnerable method with untrusted input
5. Bugs fixed (https://bugzilla.redhat.com/):
1992006 - CVE-2021-29923 golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet
2006044 - CVE-2021-39293 golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196)
2012887 - CVE-2021-38297 golang: Command-line arguments may overwrite global data
2024838 - Release of OpenShift Serverless Eventing 1.20.0
2024839 - Release of OpenShift Serverless Serving 1.20.0
5
| VAR-202103-1352 | CVE-2021-26943 | ASUS UX360CA BIOS Vulnerability in |
CVSS V2: 7.2 CVSS V3: 8.2 Severity: HIGH |
The UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary physical memory locations, including SMRAM, and execute arbitrary code in the SMM (issue 3 of 3). ASUS UX360CA BIOS Contains an unspecified vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Asus UX360CA BIOS through 303 is a notebook computer from Asus, Japan.
UX360CA BIOS through 303 on ASUS has a security vulnerability
| VAR-202104-0435 | CVE-2021-22327 | Huawei P30 memory write vulnerability |
CVSS V2: 4.3 CVSS V3: 6.5 Severity: MEDIUM |
There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient validation of the input files, successful exploit could cause certain service abnormal. Affected product versions include:HUAWEI P30 versions 10.0.0.186(C10E7R5P1), 10.0.0.186(C461E4R3P1), 10.0.0.188(C00E85R2P11), 10.0.0.188(C01E88R2P11),10.0.0.188(C605E19R1P3), 10.0.0.190(C185E4R7P1), 10.0.0.190(C431E22R2P5), 10.0.0.190(C432E22R2P5),10.0.0.190(C605E19R1P3), 10.0.0.190(C636E4R3P4), 10.0.0.192(C635E3R2P4). Huawei P30 is a smart phone of China's Huawei (Huawei) company. The vulnerability stems from the program's failure to properly validate the input file. Attackers use this vulnerability to cause abnormal program services
| VAR-202104-0437 | CVE-2021-22330 | Huawei P30 memory write out-of-bounds vulnerability |
CVSS V2: 3.3 CVSS V3: 6.5 Severity: MEDIUM |
There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input parameter, successful exploit can cause the process and the service to be abnormal. Huawei P30 is a smart phone of China's Huawei (Huawei) company. Attackers exploiting this vulnerability may cause a denial of service
| VAR-202103-1167 | CVE-2021-26810 | D-link DIR-816 A2 Code injection vulnerabilities |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter. D-link DIR-816 A2 Contains a code injection vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. D-link DIR-816 A2 is a wireless AC750 dual-band router