Rocky Linux 8 [CIQ] セキュリティ更新:apache-commons-collections/apache-commons-lang/etcの複数の脆弱性(crlsa-2020_4847)

critical Nessus プラグイン ID 359386

概要

Rocky Linuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

Rocky Linux 8ホストには、CIQ crlsa-2020_4847 アドバイザリに記載された複数の脆弱性の影響を受けるパッケージがインストールされています。

* jquery:クロスドメイン ajax リクエストによるクロスサイトスクリプティング(CVE-2015-9251)

* ブートストラップ:データターゲット属性の XSS(CVE-2016-10735)

* ブートストラップ:collapse data-parent 属性のクロスサイトスクリプティング(XSS)(CVE-2018-14040)

* ブートストラップ:ツールチップのデータコンテナプロパティのクロスサイトスクリプティング(XSS)(CVE-2018-14042)

* bootstrap: ツールチップまたはポップオーバーデータテンプレート属性の XSS (CVE-2019-8331)

* jquery:オブジェクトのプロトタイプのプロトタイプ汚染により、サービス拒否、リモートコード実行、またはプロパティインジェクションが発生(CVE-2019-11358)

* jquery:不適切な injQuery.htmlPrefilter メソッドによるクロスサイトスクリプティング(CVE-2020-11022)

* jquery: <option> 要素を含むHTMLを操作メソッドに渡すことで、信頼できないコードが実行される可能性があります(CVE-2020-11023)

* pki:Dogtag の python クライアントは、証明書を検証しません(CVE-2020-15720)

* pki-core:CA のエージェントページで「パスの長さ」制約フィールドに反映された XSS(CVE-2019-10146)

* pki-core/pki-kra:recover 認証タブの KRA の DRM エージェントページにある recoveryID 検索フィールドの XSS を反映(CVE-2019-10179)

* pki-core:CA の getcookies?url= エンドポイントにおける折り返し型 XSS(CVE-2019-10221)

* pki-core:getPk12 ページを介した折り返し型 XSS に対して KRA に脆弱性(CVE-2020-1721)

Tenableは、前述の記述ブロックをCIQセキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

CIQアドバイザリ crlsa-2020_4847のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://access.redhat.com/errata/RHSA-2020:4847

https://bugzilla.redhat.com/show_bug.cgi?id=1376706

https://bugzilla.redhat.com/show_bug.cgi?id=1399546

https://bugzilla.redhat.com/show_bug.cgi?id=1406505

https://bugzilla.redhat.com/show_bug.cgi?id=1601614

https://bugzilla.redhat.com/show_bug.cgi?id=1601617

https://bugzilla.redhat.com/show_bug.cgi?id=1666907

https://bugzilla.redhat.com/show_bug.cgi?id=1668097

https://bugzilla.redhat.com/show_bug.cgi?id=1686454

https://bugzilla.redhat.com/show_bug.cgi?id=1695901

https://bugzilla.redhat.com/show_bug.cgi?id=1701972

https://bugzilla.redhat.com/show_bug.cgi?id=1706521

https://bugzilla.redhat.com/show_bug.cgi?id=1710171

https://bugzilla.redhat.com/show_bug.cgi?id=1721684

https://bugzilla.redhat.com/show_bug.cgi?id=1724433

https://bugzilla.redhat.com/show_bug.cgi?id=1732565

https://bugzilla.redhat.com/show_bug.cgi?id=1732981

https://bugzilla.redhat.com/show_bug.cgi?id=1777579

https://bugzilla.redhat.com/show_bug.cgi?id=1805541

https://bugzilla.redhat.com/show_bug.cgi?id=1817247

https://bugzilla.redhat.com/show_bug.cgi?id=1821851

https://bugzilla.redhat.com/show_bug.cgi?id=1822246

https://bugzilla.redhat.com/show_bug.cgi?id=1824939

https://bugzilla.redhat.com/show_bug.cgi?id=1824948

https://bugzilla.redhat.com/show_bug.cgi?id=1825998

https://bugzilla.redhat.com/show_bug.cgi?id=1828406

https://bugzilla.redhat.com/show_bug.cgi?id=1842734

https://bugzilla.redhat.com/show_bug.cgi?id=1842736

https://bugzilla.redhat.com/show_bug.cgi?id=1843537

https://bugzilla.redhat.com/show_bug.cgi?id=1845447

https://bugzilla.redhat.com/show_bug.cgi?id=1850004

https://bugzilla.redhat.com/show_bug.cgi?id=1854043

https://bugzilla.redhat.com/show_bug.cgi?id=1854959

https://bugzilla.redhat.com/show_bug.cgi?id=1855273

https://bugzilla.redhat.com/show_bug.cgi?id=1855319

https://bugzilla.redhat.com/show_bug.cgi?id=1856368

https://bugzilla.redhat.com/show_bug.cgi?id=1857933

https://bugzilla.redhat.com/show_bug.cgi?id=1861911

https://bugzilla.redhat.com/show_bug.cgi?id=1869893

https://bugzilla.redhat.com/show_bug.cgi?id=1871064

https://bugzilla.redhat.com/show_bug.cgi?id=1873235

https://errata.build.resf.org/RLSA-2020:4847

http://www.nessus.org/u?3ed75902

http://www.nessus.org/u?89163e40

プラグインの詳細

深刻度: Critical

ID: 359386

ファイル名: ciq_rocky_linux_8_crlsa-2020_4847.nasl

バージョン: 1.3

タイプ: Local

公開日: 2026/10/1

更新日: 2026/10/2

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.9

パーセンタイル: 99.36

Vendor

Vendor Severity: Unknown

CVSS v2

リスクファクター: High

基本値: 7.5

現状値: 6.5

ベクトル: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS スコアのソース: CVE-2022-25762

CVSS v3

リスクファクター: Critical

基本値: 9.8

現状値: 9.4

ベクトル: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:H/RL:O/RC:C

CVSS スコアのソース: CVE-2020-1938

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2020/11/3

脆弱性公開日: 2018/1/18

CISA の既知の悪用された脆弱性の期限日: 2022/3/17, 2025/2/13

参照情報

CVE: CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14042, CVE-2019-10146, CVE-2019-10179, CVE-2019-10221, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, CVE-2020-15720, CVE-2020-1721, CVE-2020-1935, CVE-2020-1938, CVE-2020-25715, CVE-2022-25762