RHSA-2023:7622MediumCVSS 6.5
Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.7 release and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-0464 — openssl: Denial of service by excessive resource usage in verifying X509 policy constraints CVE-2023-0465 — openssl: Invalid certificate policies in leaf certificates are silently ignored CVE-2023-0466 — openssl: Certificate policy check not enabled CVE-2023-2650 — openssl: Possible DoS translating ASN.1 object identifiers CVE-2023-3446 — openssl: Excessive time spent checking DH keys and parameters CVE-2023-3817 — OpenSSL: Excessive time spent checking DH q parameter value CVE-2023-41080 — tomcat: Open Redirect vulnerability in FORM authentication
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2023:7622
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181082
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182561
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182565
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2207947
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224962
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2227852
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2235370
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7622.json