Show plain JSON{"acknowledgement": "Red Hat would like to thank Egor Dimitrenko (Positive Technologies) for reporting this issue.", "affected_release": [{"advisory": "RHSA-2022:8915", "cpe": "cpe:/a:redhat:certificate_system:9.7::el7", "package": "pki-core-0:10.5.18-24.el7pki", "product_name": "Red Hat Certificate System 9.7", "release_date": "2022-12-12T00:00:00Z"}, {"advisory": "RHSA-2022:8799", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "pki-core-0:10.5.18-24.el7_9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2022-12-06T00:00:00Z"}, {"advisory": "RHSA-2022:7470", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "pki-core:10.6-8070020220726172732.6e5cea50", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2022-11-08T00:00:00Z"}, {"advisory": "RHSA-2023:1747", "cpe": "cpe:/a:redhat:rhel_aus:8.2", "package": "pki-core:10.6-8020020221118110959.bbc64e6e", "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support", "release_date": "2023-04-12T00:00:00Z"}, {"advisory": "RHSA-2023:1747", "cpe": "cpe:/a:redhat:rhel_tus:8.2", "package": "pki-core:10.6-8020020221118110959.bbc64e6e", "product_name": "Red Hat Enterprise Linux 8.2 Telecommunications Update Service", "release_date": "2023-04-12T00:00:00Z"}, {"advisory": "RHSA-2023:1747", "cpe": "cpe:/a:redhat:rhel_e4s:8.2", "package": "pki-core:10.6-8020020221118110959.bbc64e6e", "product_name": "Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions", "release_date": "2023-04-12T00:00:00Z"}, {"advisory": "RHSA-2023:1966", "cpe": "cpe:/a:redhat:rhel_eus:8.4", "package": "pki-core:10.6-8040020221216154854.17df0a3f", "product_name": "Red Hat Enterprise Linux 8.4 Extended Update Support", "release_date": "2023-04-25T00:00:00Z"}, {"advisory": "RHSA-2023:3394", "cpe": "cpe:/a:redhat:rhel_eus:8.6", "package": "pki-core:10.6-8060020230411223433.60523a7b", "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support", "release_date": "2023-05-31T00:00:00Z"}, {"advisory": "RHSA-2022:7326", "cpe": "cpe:/a:redhat:enterprise_linux:9", "package": "pki-core-0:11.0.6-2.el9_0", "product_name": "Red Hat Enterprise Linux 9", "release_date": "2022-11-02T00:00:00Z"}], "bugzilla": {"description": "pki-core: access to external entities when parsing XML can lead to XXE", "id": "2104676", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2104676"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.5", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "status": "verified"}, "cwe": "CWE-611", "details": ["Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.", "A flaw was found in pki-core. Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests."], "mitigation": {"lang": "en:us", "value": "There is no known mitigation for this issue, please update the affected package as soon as possible."}, "name": "CVE-2022-2414", "package_state": [{"cpe": "cpe:/a:redhat:certificate_system:10", "fix_state": "Affected", "package_name": "pki-core", "product_name": "Red Hat Certificate System 10"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Out of support scope", "package_name": "pki-core", "product_name": "Red Hat Enterprise Linux 6"}], "public_date": "2022-06-10T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2022-2414\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-2414"], "threat_severity": "Important"}