RHSA-2022:0291: Important: parfait:0.5 security update
Parfait is a Java performance monitoring library that collects metrics and exposes them through a variety of outputs. It provides APIs for extracting performance metrics from the JVM and other sources. It interfaces to Performance Co-Pilot (PCP) using the Memory Mapped Value (MMV) machinery for extremely lightweight instrumentation.Security Fix(es): log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305) log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307) log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender (CVE-2021-4104) log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/parfaitto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.2.0+13999+fa2fb353 - Upgrade
Upgrade
redhat/si-unitsto a version that resolves this vulnerability.Fixed in 0.6.5-2.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/unit-apito a version that resolves this vulnerability.Fixed in 1.0-5.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-libto a version that resolves this vulnerability.Fixed in 1.0.1-6.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-parentto a version that resolves this vulnerability.Fixed in 1.0.3-3.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-seto a version that resolves this vulnerability.Fixed in 1.0.4-3.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-systemsto a version that resolves this vulnerability.Fixed in 0.7-1.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/parfait-examplesto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.2.0+13999+fa2fb353 - Upgrade
Upgrade
redhat/parfait-javadocto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.2.0+13999+fa2fb353 - Upgrade
Upgrade
redhat/pcp-parfait-agentto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.2.0+13999+fa2fb353 - Upgrade
Upgrade
redhat/si-units-javadocto a version that resolves this vulnerability.Fixed in 0.6.5-2.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/unit-api-javadocto a version that resolves this vulnerability.Fixed in 1.0-5.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-lib-javadocto a version that resolves this vulnerability.Fixed in 1.0.1-6.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-se-javadocto a version that resolves this vulnerability.Fixed in 1.0.4-3.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-systems-javadocto a version that resolves this vulnerability.Fixed in 0.7-1.module+el8+2463+615f6896
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0291?
The severity of RHSA-2022:0291 has not been explicitly stated but vulnerabilities in monitoring tools like Parfait can lead to significant security risks.
How do I fix RHSA-2022:0291?
To fix RHSA-2022:0291, update the affected packages to the latest versions provided in the Red Hat advisory.
Which packages are affected by RHSA-2022:0291?
Affected packages include parfait, si-units, unit-api, uom-lib, uom-parent, uom-se, and uom-systems among others listed in the advisory.
Is RHSA-2022:0291 related to Java performance monitoring?
Yes, RHSA-2022:0291 pertains to vulnerabilities found in the Parfait Java performance monitoring library.
What actions should I take after identifying RHSA-2022:0291 on my system?
After identifying RHSA-2022:0291, it's crucial to promptly assess the risk, update affected packages, and maintain regular system vulnerability assessments.