Site icon API Security Blog

RHEL 8 : Red Hat JBoss Enterprise Application Platform 7.4.9 Security update (Important) (RHSA-2023:0553)

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:0553 advisory.

– jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)

– bootstrap: XSS in the data-target attribute (CVE-2016-10735)

– nodejs-moment: Regular expression denial of service (CVE-2017-18214)

– bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)

– bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy (CVE-2018-14041)

– bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042)

– jquery: Prototype pollution in object’s prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)

– bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)

– jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)

– jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods (CVE-2020-11023)

– wildfly-elytron: possible timing attacks via use of unsafe comparator (CVE-2022-3143)

– jettison: parser crash by stackoverflow (CVE-2022-40149)

– jettison: memory exhaustion via user-supplied XML or JSON data (CVE-2022-40150)

– woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks (CVE-2022-40152)

– jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS (CVE-2022-42003)

– jackson-databind: use of deeply nested arrays (CVE-2022-42004)

– mina-sshd: Java unsafe deserialization vulnerability (CVE-2022-45047)

– jettison: If the value in map is the map’s self, the new new JSONObject(map) cause StackOverflowError which may lead to dos (CVE-2022-45693)

– Apache CXF: SSRF Vulnerability (CVE-2022-46364)

Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.Read More

Exit mobile version