Bug 1696000 (CVE-2019-0191)
Summary: | CVE-2019-0191 karaf: Zip-slip vulnerability via kar file | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | aileenc, chazlett, dbecker, gvarsami, jcoleman, jjoyce, jschluet, kbasil, kconner, ldimaggi, lhh, lpeer, mburns, mkolesni, nwallace, rwagner, sclewis, scohen, slinaber, tcunning, tkirby |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | karaf 4.2.3 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2019-12-10 19:24:02 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1696001 |
Description
Pedro Sampaio
2019-04-04 02:28:01 UTC
OpenDaylight was technical preview prior to OpenStack 13 and is being deprecated in OpenStack 14, refer to the following URL for more information. https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/14/html-single/release_notes/index#deprecated_functionality Statement: All versions of Red Hat OpenStack Platform's OpenDaylight contain the vulnerable code. However, the vulnerability is not exploitable given the way the library is used within OpenDaylight, and therefore no packages will be updated. OpenDaylight was technical preview prior to OpenStack 13 and deprecated in OpenStack 14. This vulnerability is out of security support scope for the following products: * Red Hat JBoss A-MQ 6 * Red Hat JBoss Fuse Service Works 6 * Red Hat JBoss Fuse 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details. This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-0191 |