{"id":"RLSA-2020:4847","summary":"Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update","details":"The Public Key Infrastructure (PKI) Core contains fundamental packages required by Rocky Enterprise Software Foundation Certificate System.\n\nSecurity Fix(es):\n\n* jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)\n\n* bootstrap: XSS in the data-target attribute (CVE-2016-10735)\n\n* bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)\n\n* bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042)\n\n* bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)\n\n* jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)\n\n* jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)\n\n* jquery: Passing HTML containing \u003coption\u003e elements to manipulation methods could result in untrusted code execution (CVE-2020-11023)\n\n* pki: Dogtag's python client does not validate certificates (CVE-2020-15720)\n\n* pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page (CVE-2019-10146)\n\n* pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab (CVE-2019-10179)\n\n* pki-core: Reflected XSS in getcookies?url= endpoint in CA (CVE-2019-10221)\n\n* pki-core: KRA vulnerable to reflected XSS via the getPk12 page (CVE-2020-1721)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.3 Release Notes linked from the References section.","modified":"2026-03-11T05:55:24.993845Z","published":"2020-11-03T12:29:58Z","upstream":["CVE-2015-9251","CVE-2016-10735","CVE-2018-14040","CVE-2018-14042","CVE-2019-10146","CVE-2019-10179","CVE-2019-10221","CVE-2019-11358","CVE-2019-8331","CVE-2020-11022","CVE-2020-11023","CVE-2020-15720","CVE-2020-1721","CVE-2020-1935","CVE-2020-1938","CVE-2020-25715","CVE-2022-25762"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2020:4847"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1376706"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1399546"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1406505"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1601614"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1601617"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1666907"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1668097"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1686454"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1695901"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1701972"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1706521"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1710171"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1721684"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1724433"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1732565"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1732981"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1777579"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1805541"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1817247"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1821851"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1822246"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1824939"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1824948"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1825998"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1828406"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1842734"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1842736"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1843537"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1845447"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1850004"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1854043"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1854959"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1855273"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1855319"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1856368"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1857933"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1861911"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1869893"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1871064"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1873235"}],"affected":[{"package":{"name":"apache-commons-collections","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/apache-commons-collections?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.2.2-10.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"apache-commons-collections","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/apache-commons-collections?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.2.2-10.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"apache-commons-lang","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/apache-commons-lang?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.6-21.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"apache-commons-lang","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/apache-commons-lang?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.6-21.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"apache-commons-net","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/apache-commons-net?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.6-3.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"apache-commons-net","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/apache-commons-net?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.6-3.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"bea-stax","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/bea-stax?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.0-16.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"glassfish-fastinfoset","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/glassfish-fastinfoset?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.13-9.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"glassfish-jaxb","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/glassfish-jaxb?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.2.11-11.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"glassfish-jaxb-api","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/glassfish-jaxb-api?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.2.12-8.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"jackson-annotations","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/jackson-annotations?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.10.0-1.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"jackson-core","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/jackson-core?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.10.0-1.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"jackson-databind","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/jackson-databind?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.10.0-1.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"jackson-jaxrs-providers","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/jackson-jaxrs-providers?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.9.9-1.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"jackson-module-jaxb-annotations","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/jackson-module-jaxb-annotations?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.7.6-4.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"jakarta-commons-httpclient","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/jakarta-commons-httpclient?distro=rocky-linux-8&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.1-28.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"jakarta-commons-httpclient","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/jakarta-commons-httpclient?distro=rocky-linux-8&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.1-28.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"javassist","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/javassist?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.18.1-8.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"javassist","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/javassist?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.18.1-8.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"ldapjdk","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/ldapjdk?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.22.0-1.module+el8.4.0+418+b7ae1d4a"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"pki-servlet-engine","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/pki-servlet-engine?distro=rocky-linux-8-4-legacy&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:9.0.30-1.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"python-nss","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/python-nss?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.0.1-10.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"relaxngDatatype","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/relaxngDatatype?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2011.1-7.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"resteasy","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/resteasy?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.0.26-3.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"slf4j","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slf4j?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.7.25-4.module+el8.5.0+697+f586bb30"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"slf4j","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slf4j?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.7.25-4.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"slf4j","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slf4j?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.7.25-4.module+el8.3.0+133+b8b54b58"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"stax-ex","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/stax-ex?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.7.7-8.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"velocity","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/velocity?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.7-24.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"velocity","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/velocity?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.7-24.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xalan-j2","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xalan-j2?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.7.1-38.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xalan-j2","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xalan-j2?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.7.1-38.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xerces-j2","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xerces-j2?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.11.0-34.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xerces-j2","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xerces-j2?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.11.0-34.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xml-commons-apis","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xml-commons-apis?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.4.01-25.module+el8.5.0+697+f586bb30"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xml-commons-apis","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xml-commons-apis?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.4.01-25.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xml-commons-apis","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xml-commons-apis?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.4.01-25.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xml-commons-resolver","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xml-commons-resolver?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2-26.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xml-commons-resolver","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xml-commons-resolver?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2-26.module+el8.3.0+74+855e3f5d"}],"database_specific":{"yum_repository":"PowerTools"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xmlstreambuffer","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xmlstreambuffer?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.5.4-8.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}},{"package":{"name":"xsom","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/xsom?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0-19.20110809svn.module+el8.3.0+53+ea062990"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:4847.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}