Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

Synopsis

Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

Type/Severity

Security Advisory: Moderate

Topic

An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.

Security Fix(es):

  • jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)
  • bootstrap: XSS in the data-target attribute (CVE-2016-10735)
  • bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)
  • bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042)
  • bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)
  • jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)
  • jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)
  • jquery: Passing HTML containing
  • pki: Dogtag's python client does not validate certificates (CVE-2020-15720)
  • pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page (CVE-2019-10146)
  • pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab (CVE-2019-10179)
  • pki-core: Reflected XSS in getcookies?url= endpoint in CA (CVE-2019-10221)
  • pki-core: KRA vulnerable to reflected XSS via the getPk12 page (CVE-2020-1721)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 1376706 - restore SerialNumber tag in caManualRenewal xml
  • BZ - 1399546 - CVE-2015-9251 jquery: Cross-site scripting via cross-domain ajax requests
  • BZ - 1406505 - KRA ECC installation failed with shared tomcat
  • BZ - 1601614 - CVE-2018-14040 bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
  • BZ - 1601617 - CVE-2018-14042 bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip
  • BZ - 1666907 - CC: Enable AIA OCSP cert checking for entire cert chain
  • BZ - 1668097 - CVE-2016-10735 bootstrap: XSS in the data-target attribute
  • BZ - 1686454 - CVE-2019-8331 bootstrap: XSS in the tooltip or popover data-template attribute
  • BZ - 1695901 - CVE-2019-10179 pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab
  • BZ - 1701972 - CVE-2019-11358 jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection
  • BZ - 1706521 - CA - SubjectAltNameExtInput does not display text fields to the enrollment page
  • BZ - 1710171 - CVE-2019-10146 pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page
  • BZ - 1721684 - Rebase pki-servlet-engine to 9.0.30
  • BZ - 1724433 - caTransportCert.cfg contains MD2/MD5withRSA as signingAlgsAllowed.
  • BZ - 1732565 - CVE-2019-10221 pki-core: Reflected XSS in getcookies?url= endpoint in CA
  • BZ - 1732981 - When nuxwdog is enabled pkidaemon status shows instances as stopped.
  • BZ - 1777579 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page
  • BZ - 1805541 - [RFE] CA Certificate Transparency with Embedded Signed Certificate Time stamp
  • BZ - 1817247 - Upgrade to 10.8.3 breaks PKI Tomcat Server
  • BZ - 1821851 - [RFE] Provide SSLEngine via JSSProvider for use with PKI
  • BZ - 1822246 - JSS - NativeProxy never calls releaseNativeResources - Memory Leak
  • BZ - 1824939 - JSS: add RSA PSS support - RHEL 8.3
  • BZ - 1824948 - add RSA PSS support - RHEL 8.3
  • BZ - 1825998 - CertificatePoliciesExtDefault MAX_NUM_POLICIES hardcoded limit
  • BZ - 1828406 - CVE-2020-11022 jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  • BZ - 1842734 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-8]
  • BZ - 1842736 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-8]
  • BZ - 1843537 - Able to Perform PKI CLI operations like cert request and approval without nssdb password
  • BZ - 1845447 - pkispawn fails in FIPS mode: AJP connector has secretRequired="true" but no secret
  • BZ - 1850004 - CVE-2020-11023 jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  • BZ - 1854043 - /usr/bin/PrettyPrintCert is failing with a ClassNotFoundException
  • BZ - 1854959 - ca-profile-add with Netscape extensions nsCertSSLClient and nsCertEmail in the profile gets stuck in processing
  • BZ - 1855273 - CVE-2020-15720 pki: Dogtag's python client does not validate certificates
  • BZ - 1855319 - Not able to launch pkiconsole
  • BZ - 1856368 - kra-key-generate request is failing
  • BZ - 1857933 - CA Installation is failing with ncipher v12.30 HSM
  • BZ - 1861911 - pki cli ca-cert-request-approve hangs over crmf request from client-cert-request
  • BZ - 1869893 - Common certificates are missing in CS.cfg on shared PKI instance
  • BZ - 1871064 - replica install failing during pki-ca component configuration
  • BZ - 1873235 - pki ca-user-cert-add with secure port failed with 'SSL_ERROR_INAPPROPRIATE_FALLBACK_ALERT'

CVEs

References