The vendor explicitly identifies these products as affected by this CVE.
- org.eclipse.jgit as a component of A-MQ Clients 2
- org.eclipse.jgit as a component of Cryostat 3
- org.eclipse.jgit as a component of Logging Subsystem for Red Hat OpenShift
- org.eclipse.jgit as a component of Red Hat build of Apicurio Registry 2
- org.eclipse.jgit as a component of Red Hat build of Apicurio Registry 3
- org.eclipse.jgit as a component of Red Hat Fuse 7
- org.eclipse.jgit as a component of Red Hat Integration Camel K 1
- org.eclipse.jgit as a component of Red Hat JBoss Enterprise Application Platform 7
- org.eclipse.jgit as a component of Red Hat Process Automation 7
- org.eclipse.jgit as a component of Red Hat Single Sign-On 7
- org.eclipse.jgit as a component of streams for Apache Kafka
- Summary
- A flaw was found in Eclipse JGit. This vulnerability can allow information disclosure, denial of service, and other security issues when parsing XML files.
- Remediation
- Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
