Red Hat Alert
2360Warning Date
Severity Level
Warning Number
Target Sector
10 February, 2022
● High
2022-4357
All
Description:
Red Hat has released security updates to address serveral vulnerabilities in the following products:
- Red Hat AMQ Streams 1.6.7
- Red Hat JBoss Middleware
- Red Hat AMQ Streams 2.0.1
- Red Hat JBoss Middleware
- aide
- Red Hat Enterprise Linux Server - Extended Life Cycle Support
- Red Hat Enterprise Linux Workstation
- Red Hat Enterprise Linux Server
- Red Hat Ansible Automation Platform 2.0 ansible-runner
- Red Hat Ansible Automation Platform
- RHV Manager (ovirt-engine)
- Red Hat Virtualization Manager
- Red Hat Ansible Ansible Tower 3.8
- Red Hat Ansible Automation Platform
- Red Hat OpenShift GitOps
- .NET 5.0
- Red Hat Enterprise Linux for x86_64
- Red Hat JBoss Data Virtualization 6.4.8.SP1
- Red Hat JBoss Middleware
- .NET 5.0 on RHEL 7
- dotNET on RHEL (for RHEL Server)
- dotNET on RHEL (for RHEL Workstation)
- .NET 6.0 on RHEL 7
- dotNET on RHEL (for RHEL Server)
- dotNET on RHEL (for RHEL Workstation)
- Red Hat Integration - Service Registry
- OpenShift Container Platform 4.9.19
- Red Hat OpenShift Container Platform
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code –remotely
- SQL injection
- Buffer overflow
- Escalation of privilege
Best practice and Recommendations:
The CERT team encourages users to review Red Hat security advisory and apply the necessary updates:
- https://access.redhat.com/errata/RHSA-2022:0467
- https://access.redhat.com/errata/RHSA-2022:0469
- https://access.redhat.com/errata/RHSA-2022:0472
- https://access.redhat.com/errata/RHSA-2022:0473
- https://access.redhat.com/errata/RHSA-2022:0474
- https://access.redhat.com/errata/RHSA-2022:0475
- https://access.redhat.com/errata/RHSA-2022:0482
- https://access.redhat.com/errata/RHSA-2022:0476
- https://access.redhat.com/errata/RHSA-2022:0477
- https://access.redhat.com/errata/RHSA-2022:0495
- https://access.redhat.com/errata/RHSA-2022:0496
- https://access.redhat.com/errata/RHSA-2022:0497
- https://access.redhat.com/errata/RHSA-2022:0499
- https://access.redhat.com/errata/RHSA-2022:0500
- https://access.redhat.com/errata/RHSA-2022:0501
- https://access.redhat.com/errata/RHSA-2022:0339