-
Bug
-
Resolution: Done-Errata
-
Major
-
7.13.1.GA
-
False
-
None
-
False
-
Release Notes
-
-
-
-
-
-
CR1
-
https://github.com/kiegroup/droolsjbpm-build-bootstrap/pull/2202, https://github.com/kiegroup/appformer/pull/1374, https://github.com/kiegroup/droolsjbpm-build-bootstrap/pull/2280, https://github.com/kiegroup/appformer/pull/1383, https://github.com/kiegroup/kie-wb-common/pull/3808, https://github.com/kiegroup/jbpm-wb/pull/1589, https://github.com/kiegroup/droolsjbpm-build-bootstrap/pull/2279, https://github.com/kiegroup/appformer/pull/1384, https://github.com/kiegroup/kie-wb-common/pull/3807, https://github.com/kiegroup/jbpm-wb/pull/1590
-
---
-
---
-
-
-
2023 Week 03-05 (from Jan 16), 2023 Week 06-08 (from Feb 6), 2023 Week 09-11 (from Feb 27), 2023 Week 12-14 (from Mar 20), 2023 Week 15-17 (from Apr 10), 2023 Week 18-20 (from May 1)
Security Tracking Issue
Do not make this issue public.
Impact: Important
Reported Date: 23-Nov-2022
Resolve Bug By: 22-Jan-2023
In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then.
Please see the Security Errata Policy for further details: https://docs.engineering.redhat.com/x/9kKpDw
Flaw:
CVE-2022-45047 mina-sshd: Java unsafe deserialization vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=2145194
Removing RHDM entry from the CVE page as the distribution files for Red Hat Decision Manager will be replaced with Red Hat Process Automation Manager files. RHDM is no longer being shipped separately from 7.13 onwards :
https://access.redhat.com/documentation/en-us/red_hat_decision_manager/7.13/html-single/release_notes_for_red_hat_decision_manager_7.13/index#unified_product_deliverable_and_deprecation_of_red_hat_decision_manager_distribution_files
- is blocked by
-
WFLY-17832 org.apache.sshd module take precedence over classloader from application war
- Open
- links to
-
RHSA-2023:118922 Red Hat Process Automation Manager 7.13.4 security update