Bug 2246070 (CVE-2023-44483)
Summary: | CVE-2023-44483 santuario: Private Key disclosure in debug-log output | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | ybuenos |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aileenc, asoldano, bbaranow, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, cmiranda, darran.lofthouse, dkreling, dosoudil, drichtar, eric.wittmann, fjuma, fmariani, fmongiar, gmalinko, ivassile, iweiss, janstey, jcantril, jnethert, jolee, jpoth, jschatte, jstastny, lgao, mosmerov, msochure, mstefank, msvehla, mulliken, nwallace, pantinor, pcongius, pdelbell, pdrozd, peholase, periklis, pjindal, pmackay, pskopek, rowaters, rstancel, smaestri, sthorger, tcunning, tom.jenkinson, yfang |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | santuario 2.2.6, santuario 2.3.4, santuario 3.0.3 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2246071, 2260292, 2260293, 2246072 | ||
Bug Blocks: | 2245905 |
Description
ybuenos
2023-10-25 09:06:09 UTC
Created xml-security-c tracking bugs for this issue: Affects: epel-all [bug 2246071] Affects: fedora-all [bug 2246072] Created xml-security-c tracking bugs for this issue: Affects: epel-all [bug 2260292] Affects: fedora-all [bug 2260293] This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2024:0712 https://access.redhat.com/errata/RHSA-2024:0712 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2024:0710 https://access.redhat.com/errata/RHSA-2024:0710 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2024:0711 https://access.redhat.com/errata/RHSA-2024:0711 This issue has been addressed in the following products: EAP 7.4.15 Via RHSA-2024:0714 https://access.redhat.com/errata/RHSA-2024:0714 This issue has been addressed in the following products: RHBOAC camel-quarkus 3 (camel-4.0/quarkus-3.2) Via RHSA-2024:0789 https://access.redhat.com/errata/RHSA-2024:0789 This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 8 Via RHSA-2024:0799 https://access.redhat.com/errata/RHSA-2024:0799 This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 9 Via RHSA-2024:0800 https://access.redhat.com/errata/RHSA-2024:0800 This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 7 Via RHSA-2024:0798 https://access.redhat.com/errata/RHSA-2024:0798 This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2024:0801 https://access.redhat.com/errata/RHSA-2024:0801 This issue has been addressed in the following products: Red Hat Single Sign-On Via RHSA-2024:0804 https://access.redhat.com/errata/RHSA-2024:0804 Marking EAP-8 as not affected because EAP 8 GA was released with the fixed version. This issue has been addressed in the following products: Red Hat build of Apache Camel 3.20.6 for Spring Boot Via RHSA-2024:3708 https://access.redhat.com/errata/RHSA-2024:3708 |