Oval Definition:oval:com.redhat.rhsa:def:20203176
Revision Date:2020-07-28Version:636
Title:RHSA-2020:3176: postgresql-jdbc security update (Important)
Description:PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.

Security Fix(es):

  • postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692)

    This update introduces a backwards incompatible change required to resolve this issue. Refer to the Red Hat Knowledgebase article 5266441 linked to in the References section for information on how to re-enable the old insecure behavior.

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2020-13692
    RHSA-2020:3176
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • postgresql-jdbc is earlier than 0:42.2.3-3.el8_2
  • AND postgresql-jdbc is signed with Red Hat redhatrelease2 key
  • postgresql-jdbc-javadoc is earlier than 0:42.2.3-3.el8_2
  • AND postgresql-jdbc-javadoc is signed with Red Hat redhatrelease2 key
  • BACK