RHSA-2022:0294: Important: parfait:0.5 security update
Parfait is a Java performance monitoring library that collects metrics and exposes them through a variety of outputs. It provides APIs for extracting performance metrics from the JVM and other sources. It interfaces to Performance Co-Pilot (PCP) using the Memory Mapped Value (MMV) machinery for extremely lightweight instrumentation.Security Fix(es): log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305) log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307) log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender (CVE-2021-4104) log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/parfaitto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.1.0+14000+df5fdac7 - Upgrade
Upgrade
redhat/si-unitsto a version that resolves this vulnerability.Fixed in 0.6.5-2.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/unit-apito a version that resolves this vulnerability.Fixed in 1.0-5.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-libto a version that resolves this vulnerability.Fixed in 1.0.1-6.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-parentto a version that resolves this vulnerability.Fixed in 1.0.3-3.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-seto a version that resolves this vulnerability.Fixed in 1.0.4-3.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-systemsto a version that resolves this vulnerability.Fixed in 0.7-1.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/parfait-examplesto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.1.0+14000+df5fdac7 - Upgrade
Upgrade
redhat/parfait-javadocto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.1.0+14000+df5fdac7 - Upgrade
Upgrade
redhat/pcp-parfait-agentto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.1.0+14000+df5fdac7 - Upgrade
Upgrade
redhat/si-units-javadocto a version that resolves this vulnerability.Fixed in 0.6.5-2.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/unit-api-javadocto a version that resolves this vulnerability.Fixed in 1.0-5.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-lib-javadocto a version that resolves this vulnerability.Fixed in 1.0.1-6.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-se-javadocto a version that resolves this vulnerability.Fixed in 1.0.4-3.module+el8+2463+615f6896 - Upgrade
Upgrade
redhat/uom-systems-javadocto a version that resolves this vulnerability.Fixed in 0.7-1.module+el8+2463+615f6896 - Upgrade
Upgrade
parfaitto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.1.0+14000+df5fdac7 - Upgrade
Upgrade
parfait-examplesto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.1.0+14000+df5fdac7 - Upgrade
Upgrade
parfait-javadocto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.1.0+14000+df5fdac7 - Upgrade
Upgrade
pcp-parfait-agentto a version that resolves this vulnerability.Fixed in 0.5.4-4.module+el8.1.0+14000+df5fdac7 - Upgrade
Upgrade
si-unitsto a version that resolves this vulnerability.Fixed in 0.6.5-2.module+el8+2463+615f6896 - Upgrade
Upgrade
si-units-javadocto a version that resolves this vulnerability.Fixed in 0.6.5-2.module+el8+2463+615f6896 - Upgrade
Upgrade
unit-apito a version that resolves this vulnerability.Fixed in 1.0-5.module+el8+2463+615f6896 - Upgrade
Upgrade
unit-api-javadocto a version that resolves this vulnerability.Fixed in 1.0-5.module+el8+2463+615f6896 - Upgrade
Upgrade
uom-libto a version that resolves this vulnerability.Fixed in 1.0.1-6.module+el8+2463+615f6896 - Upgrade
Upgrade
uom-lib-javadocto a version that resolves this vulnerability.Fixed in 1.0.1-6.module+el8+2463+615f6896 - Upgrade
Upgrade
uom-parentto a version that resolves this vulnerability.Fixed in 1.0.3-3.module+el8+2463+615f6896 - Upgrade
Upgrade
uom-seto a version that resolves this vulnerability.Fixed in 1.0.4-3.module+el8+2463+615f6896 - Upgrade
Upgrade
uom-se-javadocto a version that resolves this vulnerability.Fixed in 1.0.4-3.module+el8+2463+615f6896 - Upgrade
Upgrade
uom-systemsto a version that resolves this vulnerability.Fixed in 0.7-1.module+el8+2463+615f6896 - Upgrade
Upgrade
uom-systems-javadocto a version that resolves this vulnerability.Fixed in 0.7-1.module+el8+2463+615f6896
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0294?
The security severity level of RHSA-2022:0294 can be categorized as moderate.
How do I fix RHSA-2022:0294?
To fix RHSA-2022:0294, upgrade to the latest versions of the affected packages listed in the advisory.
Which packages are affected by RHSA-2022:0294?
RHSA-2022:0294 affects multiple packages, including parfait, si-units, unit-api, and uom-lib among others.
Is RHSA-2022:0294 applicable to all Red Hat environments?
RHSA-2022:0294 is specifically applicable to Red Hat Enterprise Linux 8 environments.
What is Parfait in the context of RHSA-2022:0294?
Parfait is a Java performance monitoring library that collects metrics from the JVM and other sources, which is affected by RHSA-2022:0294.