The vendor explicitly identifies these products as affected by this CVE.
- openshift-logging/elasticsearch6-rhel8 as a component of Logging Subsystem for Red Hat OpenShift
- jettison as a component of Red Hat build of Quarkus
- jettison as a component of Red Hat Decision Manager 7
- jettison-javadoc as a component of Red Hat Enterprise Linux 7
- jettison.src as a component of Red Hat Enterprise Linux 7
- jettison as a component of Red Hat Fuse 7
- jettison as a component of Red Hat Integration Camel K 1
- jettison as a component of Red Hat JBoss Data Grid 7
- jettison as a component of Red Hat JBoss Data Virtualization 6
- eap6-jettison as a component of Red Hat JBoss Enterprise Application Platform 6
- jboss-on as a component of Red Hat JBoss Enterprise Application Platform 6
- jbossas-modules-eap as a component of Red Hat JBoss Enterprise Application Platform 6
- Summary
- A stack-based buffer overflow vulnerability was found in Jettison, where parsing an untrusted XML or JSON data may lead to a crash. This flaw allows an attacker to supply content that causes the parser to crash by writing outside the memory bounds if the parser is running on user-supplied input, resulting in a denial of service attack.
- Remediation
- Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
