Vulnerability Database
Blog
FAQ
Docs
RHSA-2024:3061
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2024:3061
Import Source
https://security.access.redhat.com/data/osv/RHSA-2024:3061.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2024:3061
Related
CVE-2020-36518
Published
2024-09-13T15:48:09Z
Modified
2024-10-24T01:45:16Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security update
Details
References
https://access.redhat.com/errata/RHSA-2024:3061
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.10_release_notes/index
https://bugzilla.redhat.com/show_bug.cgi?id=2064698
https://issues.redhat.com/browse/RHEL-12764
https://issues.redhat.com/browse/RHEL-12765
https://issues.redhat.com/browse/RHEL-16724
https://issues.redhat.com/browse/RHEL-19140
https://issues.redhat.com/browse/RHEL-22445
https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3061.json
https://access.redhat.com/security/cve/CVE-2020-36518
https://www.cve.org/CVERecord?id=CVE-2020-36518
https://nvd.nist.gov/vuln/detail/CVE-2020-36518
https://github.com/advisories/GHSA-57j2-w4cx-62h2
Affected packages
Red Hat:enterprise_linux:8::appstream
/
apache-commons-collections
Package
Name
apache-commons-collections
Purl
pkg:rpm/redhat/apache-commons-collections
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.2.2-10.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
apache-commons-lang
Package
Name
apache-commons-lang
Purl
pkg:rpm/redhat/apache-commons-lang
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.6-21.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
apache-commons-net
Package
Name
apache-commons-net
Purl
pkg:rpm/redhat/apache-commons-net
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.6-3.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
bea-stax
Package
Name
bea-stax
Purl
pkg:rpm/redhat/bea-stax
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-16.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
bea-stax-api
Package
Name
bea-stax-api
Purl
pkg:rpm/redhat/bea-stax-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-16.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
fasterxml-oss-parent
Package
Name
fasterxml-oss-parent
Purl
pkg:rpm/redhat/fasterxml-oss-parent
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:49-1.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
glassfish-fastinfoset
Package
Name
glassfish-fastinfoset
Purl
pkg:rpm/redhat/glassfish-fastinfoset
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.13-9.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb
Package
Name
glassfish-jaxb
Purl
pkg:rpm/redhat/glassfish-jaxb
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-12.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-api
Package
Name
glassfish-jaxb-api
Purl
pkg:rpm/redhat/glassfish-jaxb-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.12-8.module+el8.10.0+21035+a01f6469
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-core
Package
Name
glassfish-jaxb-core
Purl
pkg:rpm/redhat/glassfish-jaxb-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-12.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-runtime
Package
Name
glassfish-jaxb-runtime
Purl
pkg:rpm/redhat/glassfish-jaxb-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-12.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
glassfish-jaxb-txw2
Package
Name
glassfish-jaxb-txw2
Purl
pkg:rpm/redhat/glassfish-jaxb-txw2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.11-12.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
jackson-annotations
Package
Name
jackson-annotations
Purl
pkg:rpm/redhat/jackson-annotations
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14.2-1.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
jackson-bom
Package
Name
jackson-bom
Purl
pkg:rpm/redhat/jackson-bom
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14.2-1.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
jackson-core
Package
Name
jackson-core
Purl
pkg:rpm/redhat/jackson-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14.2-1.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
jackson-databind
Package
Name
jackson-databind
Purl
pkg:rpm/redhat/jackson-databind
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14.2-1.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
jackson-jaxrs-json-provider
Package
Name
jackson-jaxrs-json-provider
Purl
pkg:rpm/redhat/jackson-jaxrs-json-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14.2-1.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
jackson-jaxrs-providers
Package
Name
jackson-jaxrs-providers
Purl
pkg:rpm/redhat/jackson-jaxrs-providers
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14.2-1.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
jackson-module-jaxb-annotations
Package
Name
jackson-module-jaxb-annotations
Purl
pkg:rpm/redhat/jackson-module-jaxb-annotations
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14.2-2.module+el8.10.0+21055+7d27fa3b
Red Hat:enterprise_linux:8::appstream
/
jackson-modules-base
Package
Name
jackson-modules-base
Purl
pkg:rpm/redhat/jackson-modules-base
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14.2-2.module+el8.10.0+21055+7d27fa3b
Red Hat:enterprise_linux:8::appstream
/
jackson-parent
Package
Name
jackson-parent
Purl
pkg:rpm/redhat/jackson-parent
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.14-1.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
jakarta-commons-httpclient
Package
Name
jakarta-commons-httpclient
Purl
pkg:rpm/redhat/jakarta-commons-httpclient
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.1-28.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
javassist
Package
Name
javassist
Purl
pkg:rpm/redhat/javassist
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.18.1-8.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
javassist-javadoc
Package
Name
javassist-javadoc
Purl
pkg:rpm/redhat/javassist-javadoc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.18.1-8.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
pki-servlet-engine
Package
Name
pki-servlet-engine
Purl
pkg:rpm/redhat/pki-servlet-engine
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:9.0.62-1.module+el8.10.0+21257+2b5308b5
Red Hat:enterprise_linux:8::appstream
/
relaxngDatatype
Package
Name
relaxngDatatype
Purl
pkg:rpm/redhat/relaxngDatatype
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2011.1-7.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
slf4j
Package
Name
slf4j
Purl
pkg:rpm/redhat/slf4j
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.25-4.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
slf4j-jdk14
Package
Name
slf4j-jdk14
Purl
pkg:rpm/redhat/slf4j-jdk14
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.25-4.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
stax-ex
Package
Name
stax-ex
Purl
pkg:rpm/redhat/stax-ex
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.7-8.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
velocity
Package
Name
velocity
Purl
pkg:rpm/redhat/velocity
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7-24.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
xalan-j2
Package
Name
xalan-j2
Purl
pkg:rpm/redhat/xalan-j2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.7.1-38.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
xerces-j2
Package
Name
xerces-j2
Purl
pkg:rpm/redhat/xerces-j2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.11.0-34.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
xml-commons-apis
Package
Name
xml-commons-apis
Purl
pkg:rpm/redhat/xml-commons-apis
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.4.01-25.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
xml-commons-resolver
Package
Name
xml-commons-resolver
Purl
pkg:rpm/redhat/xml-commons-resolver
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2-26.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
xmlstreambuffer
Package
Name
xmlstreambuffer
Purl
pkg:rpm/redhat/xmlstreambuffer
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.4-8.module+el8.10.0+20993+d0f024b0
Red Hat:enterprise_linux:8::appstream
/
xsom
Package
Name
xsom
Purl
pkg:rpm/redhat/xsom
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0-19.20110809svn.module+el8.10.0+20993+d0f024b0
RHSA-2024:3061 - OSV