ALSA-2022:0290

Source
https://errata.almalinux.org/8/ALSA-2022-0290.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2022:0290.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2022:0290
Related
Published
2022-01-26T14:27:19Z
Modified
2022-01-27T20:23:26Z
Summary
Important: parfait:0.5 security update
Details

Parfait is a Java performance monitoring library that collects metrics and exposes them through a variety of outputs. It provides APIs for extracting performance metrics from the JVM and other sources. It interfaces to Performance Co-Pilot (PCP) using the Memory Mapped Value (MMV) machinery for extremely lightweight instrumentation.

Security Fix(es):

  • log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305)

  • log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307)

  • log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender (CVE-2021-4104)

  • log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8 / parfait

Package

Name
parfait

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-4.module_el8.5.0+235+62ea7738

AlmaLinux:8 / parfait

Package

Name
parfait

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-4.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / parfait-examples

Package

Name
parfait-examples

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-4.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / parfait-examples

Package

Name
parfait-examples

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-4.module_el8.5.0+235+62ea7738

AlmaLinux:8 / parfait-javadoc

Package

Name
parfait-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-4.module_el8.5.0+235+62ea7738

AlmaLinux:8 / parfait-javadoc

Package

Name
parfait-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-4.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / pcp-parfait-agent

Package

Name
pcp-parfait-agent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-4.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / pcp-parfait-agent

Package

Name
pcp-parfait-agent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-4.module_el8.5.0+235+62ea7738

AlmaLinux:8 / si-units

Package

Name
si-units

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.5-2.module_el8.5.0+235+62ea7738

AlmaLinux:8 / si-units

Package

Name
si-units

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.5-2.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / si-units-javadoc

Package

Name
si-units-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.5-2.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / si-units-javadoc

Package

Name
si-units-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.5-2.module_el8.5.0+235+62ea7738

AlmaLinux:8 / unit-api

Package

Name
unit-api

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0-5.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / unit-api

Package

Name
unit-api

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0-5.module_el8.5.0+235+62ea7738

AlmaLinux:8 / unit-api-javadoc

Package

Name
unit-api-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0-5.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / unit-api-javadoc

Package

Name
unit-api-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0-5.module_el8.5.0+235+62ea7738

AlmaLinux:8 / uom-lib

Package

Name
uom-lib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1-6.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / uom-lib

Package

Name
uom-lib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1-6.module_el8.5.0+235+62ea7738

AlmaLinux:8 / uom-lib-javadoc

Package

Name
uom-lib-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1-6.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / uom-lib-javadoc

Package

Name
uom-lib-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1-6.module_el8.5.0+235+62ea7738

AlmaLinux:8 / uom-parent

Package

Name
uom-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.3-3.module_el8.5.0+235+62ea7738

AlmaLinux:8 / uom-parent

Package

Name
uom-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.3-3.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / uom-se

Package

Name
uom-se

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.4-3.module_el8.5.0+235+62ea7738

AlmaLinux:8 / uom-se

Package

Name
uom-se

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.4-3.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / uom-se-javadoc

Package

Name
uom-se-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.4-3.module_el8.5.0+235+62ea7738

AlmaLinux:8 / uom-se-javadoc

Package

Name
uom-se-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.4-3.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / uom-systems

Package

Name
uom-systems

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7-1.module_el8.5.0+235+62ea7738

AlmaLinux:8 / uom-systems

Package

Name
uom-systems

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7-1.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / uom-systems-javadoc

Package

Name
uom-systems-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7-1.module_el8.5.0+2610+de2b8c0b

AlmaLinux:8 / uom-systems-javadoc

Package

Name
uom-systems-javadoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7-1.module_el8.5.0+235+62ea7738