-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: postgresql-jdbc security update Advisory ID: RHSA-2020:3283-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:3283 Issue date: 2020-08-03 CVE Names: CVE-2020-13692 ==================================================================== 1. Summary: An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.0) - noarch 3. Description: PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database. Security Fix(es): * postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) This update introduces a backwards incompatible change required to resolve this issue. Refer to the Red Hat Knowledgebase article 5266441 linked to in the References section for information on how to re-enable the old insecure behavior. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1852985 - CVE-2020-13692 postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.0): Source: postgresql-jdbc-42.2.3-3.el8_0.src.rpm noarch: postgresql-jdbc-42.2.3-3.el8_0.noarch.rpm postgresql-jdbc-javadoc-42.2.3-3.el8_0.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-13692 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/articles/5266441 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXyg2tNzjgjWX9erEAQhSIhAApjHVNIzxMJGENoOUpZROYmAPeOpqxVWO io3NL8540r5DbCKR0yCBXLS1U95zDoZUEF2I3rVwEwcrfakLGQIbcXcDKiz5I6Hn WvNMLktgIGnTOTUeLO5a0ysS8NiN+1jy4VOrI+ztBPqU27wcSnWiyIebm6UKvNBi ILwcm2BBh/ZrW13+Rhx611oeKdH4ZRgpXE310E1kDv9mt3okGrJw5PJHgU/eCush Z9j6Dl4Dae0GlULtGY7N5I+zxQyh0E/zru8ETbiUyqFkXDSPg4ui2Tw2oM8WQA1+ W5PPpz/3q499rM8hhJROKyxywR9qIbi8gHwzgs5V9sXCZDTuLi1lHvAjo66g3BgL RVl5SzuGbxbzVAPpmwOgUNK60L/QecBxMSqA++//c9c5It+oef1B+sHNf863hgVN /ZioD87UFpU1IbXBRWyTYqanoUX4YaeeGoE+HM9ooeDWV9r2yQ3QtKK6gqHc3C9D PEqtzn7Axor4jGKGqYRaF08x2edTWjSVe5lxioFnjODS360Yg/BWnekqydeCQBIC PjpZLo8s956I0pGHNI7ilVQjL44qBhF1pwnnBdmevYiC+qe9jEMV24stjOz7Mbxj m1A+CnpHsL6+UsXClSVSTZQW6UmeuiMjiTUrCiVg8FgcidjxQgwVA+adARc5vl3z EGAEoZ72OD0=llc1 -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce