Synopsis
Moderate: prometheus-jmx-exporter security update
 
Type/Severity
Security Advisory: Moderate
 
 
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
 
 
 
 
Topic
An update for prometheus-jmx-exporter is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
 
Description
Prometheus JMX Exporter is a JMX to Prometheus exporter: a collector that can be configured to scrape and expose MBeans of a JMX target.
Security Fix(es):
-  snakeyaml: Billion laughs attack via alias feature (CVE-2017-18640)
  
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.
 
Affected Products
- 
Red Hat Enterprise Linux for x86_64 8 x86_64
 
- 
Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64
 
- 
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8 x86_64
 
- 
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6 x86_64
 
- 
Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64
 
- 
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.4 x86_64
 
- 
Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64
 
- 
Red Hat Enterprise Linux Server - AUS 8.6 x86_64
 
- 
Red Hat Enterprise Linux Server - AUS 8.4 x86_64
 
- 
Red Hat Enterprise Linux for IBM z Systems 8 s390x
 
- 
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8 s390x
 
- 
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6 s390x
 
- 
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.4 s390x
 
- 
Red Hat Enterprise Linux for Power, little endian 8 ppc64le
 
- 
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8 ppc64le
 
- 
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6 ppc64le
 
- 
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.4 ppc64le
 
- 
Red Hat Enterprise Linux Server - TUS 8.8 x86_64
 
- 
Red Hat Enterprise Linux Server - TUS 8.6 x86_64
 
- 
Red Hat Enterprise Linux Server - TUS 8.4 x86_64
 
- 
Red Hat Enterprise Linux for ARM 64 8 aarch64
 
- 
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8 aarch64
 
- 
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6 aarch64
 
- 
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.4 aarch64
 
- 
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
 
- 
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
 
- 
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4 ppc64le
 
- 
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64
 
- 
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64
 
- 
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4 x86_64
 
 
Fixes
- 
BZ - 1785376
- CVE-2017-18640 snakeyaml: Billion laughs attack via alias feature
 
 
 
  
  Note:
  
  More recent versions of these packages may be available.
  Click a package name for more details.
Red Hat Enterprise Linux for x86_64 8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux Server - AUS 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux Server - AUS 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for IBM z Systems 8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | s390x | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | s390x | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | s390x | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | s390x | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for Power, little endian 8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | ppc64le | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | ppc64le | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | ppc64le | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | ppc64le | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux Server - TUS 8.8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux Server - TUS 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux Server - TUS 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for ARM 64 8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | aarch64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | aarch64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | aarch64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | aarch64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | ppc64le | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | ppc64le | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | ppc64le | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 | 
      
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4
    
      | SRPM | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.src.rpm
         | 
        SHA-256: 71c8b1190b0c299dea695a9ae3a0aef6f1c7c6b1065b55a3cd399a21a7ab54ae | 
      
    
      | x86_64 | 
    
      
        | 
          prometheus-jmx-exporter-0.12.0-6.el8.noarch.rpm
         | 
        SHA-256: e6d7dc3d672a078029363a718c1636a8e4adc07b9c17fdde9b404bd3967d8388 |