Vulnerability Database
Blog
FAQ
Docs
RHSA-2019:1529
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2019:1529
Import Source
https://security.access.redhat.com/data/osv/RHSA-2019:1529.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2019:1529
Related
CVE-2018-11784
CVE-2018-8014
CVE-2018-8034
CVE-2018-8037
Published
2024-10-21T22:15:11Z
Modified
2024-10-21T22:15:11Z
Severity
9.1 (Critical)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Calculator
Summary
Red Hat Security Advisory: pki-deps:10.6 security update
Details
References
https://access.redhat.com/errata/RHSA-2019:1529
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=1579611
https://bugzilla.redhat.com/show_bug.cgi?id=1607580
https://bugzilla.redhat.com/show_bug.cgi?id=1607582
https://bugzilla.redhat.com/show_bug.cgi?id=1636512
https://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_1529.json
https://access.redhat.com/security/cve/CVE-2018-8014
https://www.cve.org/CVERecord?id=CVE-2018-8014
https://nvd.nist.gov/vuln/detail/CVE-2018-8014
http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.89
http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.53
http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.32
http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.9
https://access.redhat.com/security/cve/CVE-2018-8034
https://www.cve.org/CVERecord?id=CVE-2018-8034
https://nvd.nist.gov/vuln/detail/CVE-2018-8034
https://access.redhat.com/security/cve/CVE-2018-8037
https://www.cve.org/CVERecord?id=CVE-2018-8037
https://nvd.nist.gov/vuln/detail/CVE-2018-8037
https://access.redhat.com/security/cve/CVE-2018-11784
https://www.cve.org/CVERecord?id=CVE-2018-11784
https://nvd.nist.gov/vuln/detail/CVE-2018-11784
http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.91
http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.34
http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.12
Affected packages
Red Hat:enterprise_linux:8::appstream
/
apache-commons-collections
Package
Name
apache-commons-collections
Purl
pkg:rpm/redhat/apache-commons-collections
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.2.2-10.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
apache-commons-lang
Package
Name
apache-commons-lang
Purl
pkg:rpm/redhat/apache-commons-lang
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.6-21.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
bea-stax
Package
Name
bea-stax
Purl
pkg:rpm/redhat/bea-stax
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-16.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
bea-stax-api
Package
Name
bea-stax-api
Purl
pkg:rpm/redhat/bea-stax-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-16.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
glassfish-fastinfoset
Package
Name
glassfish-fastinfoset
Purl
pkg:rpm/redhat/glassfish-fastinfoset
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.13-9.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb
Package
Name
glassfish-jaxb
Purl
pkg:rpm/redhat/glassfish-jaxb
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-11.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-api
Package
Name
glassfish-jaxb-api
Purl
pkg:rpm/redhat/glassfish-jaxb-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.12-8.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-core
Package
Name
glassfish-jaxb-core
Purl
pkg:rpm/redhat/glassfish-jaxb-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-11.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-runtime
Package
Name
glassfish-jaxb-runtime
Purl
pkg:rpm/redhat/glassfish-jaxb-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-11.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-txw2
Package
Name
glassfish-jaxb-txw2
Purl
pkg:rpm/redhat/glassfish-jaxb-txw2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-11.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
jackson-annotations
Package
Name
jackson-annotations
Purl
pkg:rpm/redhat/jackson-annotations
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.8-1.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
jackson-core
Package
Name
jackson-core
Purl
pkg:rpm/redhat/jackson-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.8-1.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
jackson-databind
Package
Name
jackson-databind
Purl
pkg:rpm/redhat/jackson-databind
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.8-1.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
jackson-jaxrs-json-provider
Package
Name
jackson-jaxrs-json-provider
Purl
pkg:rpm/redhat/jackson-jaxrs-json-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.8-1.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
jackson-jaxrs-providers
Package
Name
jackson-jaxrs-providers
Purl
pkg:rpm/redhat/jackson-jaxrs-providers
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.9.8-1.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
jackson-module-jaxb-annotations
Package
Name
jackson-module-jaxb-annotations
Purl
pkg:rpm/redhat/jackson-module-jaxb-annotations
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.7.6-4.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
jakarta-commons-httpclient
Package
Name
jakarta-commons-httpclient
Purl
pkg:rpm/redhat/jakarta-commons-httpclient
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.1-28.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
javassist
Package
Name
javassist
Purl
pkg:rpm/redhat/javassist
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.18.1-8.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
javassist-javadoc
Package
Name
javassist-javadoc
Purl
pkg:rpm/redhat/javassist-javadoc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.18.1-8.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
pki-servlet-4.0-api
Package
Name
pki-servlet-4.0-api
Purl
pkg:rpm/redhat/pki-servlet-4.0-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.7-14.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
pki-servlet-container
Package
Name
pki-servlet-container
Purl
pkg:rpm/redhat/pki-servlet-container
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.7-14.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
python-nss
Package
Name
python-nss
Purl
pkg:rpm/redhat/python-nss
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
python-nss-debugsource
Package
Name
python-nss-debugsource
Purl
pkg:rpm/redhat/python-nss-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
python-nss-doc
Package
Name
python-nss-doc
Purl
pkg:rpm/redhat/python-nss-doc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
python3-nss
Package
Name
python3-nss
Purl
pkg:rpm/redhat/python3-nss
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
python3-nss-debuginfo
Package
Name
python3-nss-debuginfo
Purl
pkg:rpm/redhat/python3-nss-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-10.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
relaxngDatatype
Package
Name
relaxngDatatype
Purl
pkg:rpm/redhat/relaxngDatatype
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2011.1-7.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
resteasy
Package
Name
resteasy
Purl
pkg:rpm/redhat/resteasy
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.26-3.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
slf4j
Package
Name
slf4j
Purl
pkg:rpm/redhat/slf4j
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.25-4.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
slf4j-jdk14
Package
Name
slf4j-jdk14
Purl
pkg:rpm/redhat/slf4j-jdk14
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.25-4.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
stax-ex
Package
Name
stax-ex
Purl
pkg:rpm/redhat/stax-ex
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.7-8.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
velocity
Package
Name
velocity
Purl
pkg:rpm/redhat/velocity
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7-24.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
xalan-j2
Package
Name
xalan-j2
Purl
pkg:rpm/redhat/xalan-j2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.7.1-38.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
xerces-j2
Package
Name
xerces-j2
Purl
pkg:rpm/redhat/xerces-j2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.11.0-34.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
xml-commons-apis
Package
Name
xml-commons-apis
Purl
pkg:rpm/redhat/xml-commons-apis
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.4.01-25.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
xml-commons-resolver
Package
Name
xml-commons-resolver
Purl
pkg:rpm/redhat/xml-commons-resolver
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2-26.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
xmlstreambuffer
Package
Name
xmlstreambuffer
Purl
pkg:rpm/redhat/xmlstreambuffer
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.4-8.module+el8.0.0+3248+9d514f3b
Red Hat:enterprise_linux:8::appstream
/
xsom
Package
Name
xsom
Purl
pkg:rpm/redhat/xsom
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0-19.20110809svn.module+el8.0.0+3248+9d514f3b
RHSA-2019:1529 - OSV