The following advisory data is extracted from: https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_4223.json Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment. - Packet Storm Staff ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Certificate System security and bug fix update Advisory ID: RHSA-2024:4223-03 Product: Red Hat Certificate System Advisory URL: https://access.redhat.com/errata/RHSA-2024:4223 Issue date: 2024-08-19 Revision: 03 CVE Names: ==================================================================== Summary: An update for pki-core and redhat-pki-theme is now available for Red Hat Certificate System 9.7 for RHEL 7.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description: Red Hat Certificate System is a complete implementation of an enterprise software system designed to manage enterprise public key infrastructure (PKI) deployments. Bug fix(es): * Coolkey Hardcoded RSA Max Key Size (BZ#2047831) * Add Secure Channel Support for AES-256 Keys (BZ#2121463) * TPS missing Host header field in HTTP/1.1 request message (BZ#2177785) * Add AES support for TMS server-side keygen on latest HSM / FIPS environment (BZ#2180920) * Make key wrapping algorithm configurable between AES-KWP and AES-CBC (BZ#2233158) * pkidestroy log keeps HSM token password (BZ#2253682) * Add Support for Symmetric Key Rollover (BZ#2265180) Users of Red Hat Certificate System are advised to install these updated packages. Solution: CVEs: References: https://access.redhat.com/security/updates/classification/#important