Moderate: Satellite 6.11 Release

Synopsis

Moderate: Satellite 6.11 Release

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat Satellite 6.11

Description

Red Hat Satellite is a systems management tool for Linux-based
infrastructure. It allows for provisioning, remote management, and
monitoring of multiple Linux deployments with a single centralized tool.

Security Fix(es):

  • libsolv: Heap-based buffer overflow in testcase_read() in src/testcase.c (CVE-2021-3200)
  • satellite: foreman: Authenticate remote code execution through Sendmail configuration (CVE-2021-3584)
  • candlepin: Allow unintended SCA certificate to authenticate Candlepin (CVE-2021-4142)
  • candlepin: netty: Information disclosure via the local system temporary directory (CVE-2021-21290)
  • candlepin: netty: Possible request smuggling in HTTP/2 due missing validation (CVE-2021-21295)
  • candlepin: netty: Request smuggling via content-length header (CVE-2021-21409)
  • tfm-rubygem-sidekiq: XSS via the queue name of the live-poll feature (CVE-2021-30151)
  • python-sqlparse: ReDoS via regular expression in StripComments filter (CVE-2021-32839)
  • libsolv: various flaws (CVE-2021-33928 CVE-2021-33929 CVE-2021-33930 CVE-2021-33938)
  • tfm-rubygem-puma: Inconsistent Interpretation of HTTP Requests in puma (CVE-2021-41136)
  • logback-classic: Remote code execution through JNDI call from within its configuration file (CVE-2021-42550)
  • candlepin: netty: Control chars in header names may lead to HTTP request smuggling (CVE-2021-43797)
  • python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818)
  • python3-django: Potential bypass of an upstream access control based on URL paths (CVE-2021-44420)
  • libsolv: Heap overflow (CVE-2021-44568)
  • python3-django: Various flaws (CVE-2021-45115 CVE-2021-45116 CVE-2021-45452 CVE-2022-22818)
  • tfm-rubygem-actionpack: Information leak between requests (CVE-2022-23633)
  • tfm-rubygem-puma: rubygem-rails: Information leak between requests (CVE-2022-23634)
  • python3-django: Denial-of-service possibility in file uploads (CVE-2022-23833)
  • tfm-rubygem-sidekiq: WebUI Denial of Service caused by number of days on graph (CVE-2022-23837)
  • python3-django: Various flaws (CVE-2022-28346 CVE-2022-28347)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

  • New repo layout for Satellite, Utils, Maintenance, and Client repos.
  • Support for RHEL 9 clients
  • Module-based installation on RHEL 8
  • Upgrading Satellite Server and Capsule Server installations from RHEL 7 to RHEL 8
  • Connected and Disconnected servers supported on RHEL 7 and RHEL 8
  • Inter-Server Synchronization improvements
  • Puppet integration optional and disabled by default
  • Pulp 3 updated to Python 3.8
  • Change to Capsule certificate archive
  • New default port for communication with Red Hat Subscription Management * (RHSM) API on Capsule servers
  • New Content Views Page (Content Publication workflow simplification)
  • New Hosts Page (Technology Preview)
  • Registration and preview templates
  • Simplified host content source changing
  • Improved behavior for configuring and running remote jobs
  • Provisioning improvements
  • New error signaling unsupported options in TASK-Filter
  • Virt-who configuration enhanced to support Nutanix AHV
  • Cloud Connector configuration updated
  • Improved Insights adoption

The items above are not a complete list of changes. This update also fixes
several bugs and adds various enhancements. Documentation for these changes
is available from the Release Notes document linked to in the References
section.

Solution

For Red Hat Satellite 6.11 see the following documentation for the release.
https://access.redhat.com/documentation/en-us/red_hat_satellite/6.11

The important instructions on how to upgrade are available below.
https://access.redhat.com/documentation/en-us/red_hat_satellite/6.11/html/upgrading_and_updating_red_hat_satellite

Affected Products

  • Red Hat Satellite 6.11 for RHEL 8 x86_64
  • Red Hat Satellite 6.11 for RHEL 7 x86_64
  • Red Hat Satellite Capsule 6.11 for RHEL 8 x86_64
  • Red Hat Satellite Capsule 6.11 for RHEL 7 x86_64

Fixes

  • BZ - 1459231 - [RFE] Support 'cleaning' a repo of downloaded on_demand content
  • BZ - 1473263 - Processing outputs of remote command on the smart-proxy is slow.
  • BZ - 1545000 - [RFE] As a user of Satellite, I would like to use another Satellite as my CDN.
  • BZ - 1596004 - Cannot register host with activationkey that is associated to host collections that have host count limits
  • BZ - 1609543 - concurrently creating repositories causes most of them are not visible for consumer at the end
  • BZ - 1659649 - [RFE] Shorten or handle "410 Gone" errors rather than printing a page-long trace for each
  • BZ - 1662924 - [RFE] Report that lists all the hosts on which a particular repository is enabled
  • BZ - 1685708 - Editing a host tries to inherit the operating system properties from it's host-group instead of the CV and Lifecycle Environment assigned
  • BZ - 1693733 - ensure foreman-maintain works with RHEL8 Satellite & Capsules
  • BZ - 1694659 - [RFE] Host Add-Parameter button should not float down page as new params are added.
  • BZ - 1713401 - RHEL 8 systems with OSPP applied cannot install katello-ca-consumer package from Satellite 6.5
  • BZ - 1723632 - When restarting foreman-tasks, long running tasks got forcefully killed after 20 seconds of wait.
  • BZ - 1723751 - [RFE] Provide a script-like interface to task cleanup, preventing wrong values from being entered
  • BZ - 1735540 - Virt-who-config for kubevirt does not support in API and hammer CLI
  • BZ - 1744521 - There is no way to identify the overriden Ansible variables while creating or editing an existing host
  • BZ - 1761421 - [RFE] Option to "skip-tags" on Ansible runs from Red Hat Satellite server.
  • BZ - 1770075 - Snippet template may render incorrect result when non-default scope class is used to render the main template.
  • BZ - 1771724 - Move Actions::Katello::Host::UploadPackageProfile out of dynflow
  • BZ - 1777820 - [RFE] Make hammer-cli available for RHEL 8 systems
  • BZ - 1784254 - Static recurring job failed to schedule on 2nd iteration if any of the target host record is invalid.
  • BZ - 1805028 - Issue with hammer shell while using "--fields" parameter to display host info
  • BZ - 1807258 - Cloned viewer role cannot view facts
  • BZ - 1807536 - Parent Hostgroup hammer parameter accept only name, not title
  • BZ - 1809769 - [RFE] support ability disable and remove puppetserver from Satellite and Capsules
  • BZ - 1811166 - REX job failed when you enable FIPS on RHEL 8 hosts
  • BZ - 1813624 - Consistent use of unlimited-host argument throughout CLI
  • BZ - 1819309 - [RFE] Load balanced capsules without using sticky sessions
  • BZ - 1825761 - Ansible Role execution reports do not show Ansible Icon
  • BZ - 1832858 - [RFE] Exporting a content view does not exports the description assigned to the content view.
  • BZ - 1844848 - [RFE] add "duration" column to tasks hammer and export
  • BZ - 1845471 - exclude source redhat containers by default
  • BZ - 1847825 - Incorrect text alignment for error message
  • BZ - 1851808 - Unable to set ssh password and sudo password when creating a REX job using hammer
  • BZ - 1852897 - API - ISE when using invalid status type
  • BZ - 1862140 - ipv4/6 auto-suggested address should be removed when the different domain and subnet with ipv6/4 are selected
  • BZ - 1867193 - Content Host Traces Management modal window does not respect selection done on the previously opened page
  • BZ - 1869351 - [RFE] Add ability to omit specific hosts from rh_cloud inventory upload
  • BZ - 1872688 - Remote execution will fail on client with FIPS enabled
  • BZ - 1873241 - [RFE] When choosing what capsule to use for Remote Execution into a host, use the host's "Registered through" capsule
  • BZ - 1877283 - [RFE] Request to use /etc/virt-who.conf as the default config file for virt-who plugin
  • BZ - 1878049 - Cancel button should be enabled in the capsule sync until the job completions
  • BZ - 1881668 - hammer user list --help has invalid --order example
  • BZ - 1883612 - [RFE] - Needs Dot Bullet to distinguised environment for Composite Content View on Red Hat Satellite Web UI
  • BZ - 1883816 - Appropriate error message to be shown when creating authsource with same name as existing authsource.
  • BZ - 1886780 - [Sat 6.8/UI/Bug] Refresh icon doesn't go away
  • BZ - 1893059 - Satellite 6.8 Remote Execution fails on RHEL 8.2 clients with DEFAULT:NO-SHA1 crypto policy
  • BZ - 1896628 - Hammer Command Fails to List Job Invocation Details if Organization is Used
  • BZ - 1898656 - [RFE] Include status of REX jobs on the Satellite Dashboard
  • BZ - 1899481 - [RFE] - Tasks: Need Word Wrap for Long Commands
  • BZ - 1902047 - [RFE] In the message "Repository cannot be deleted since it has already been included in a published Content View" , include the name of CV and it's versions
  • BZ - 1902314 - [RFE] Introduce check-only or dry-run feature for any kind of Ansible based job execution from Satellite 6
  • BZ - 1906023 - ssh debug logging on FIPS causes REX job failure with OpenSSL::Digest::DigestError
  • BZ - 1907795 - Remove the MS Windows provisioning Templates from the RedHat Satellite 6
  • BZ - 1910433 - REX is not possible on RHEL 8 when FUTURE crypto policy is set from Satellite 6.8
  • BZ - 1911545 - Epoch version is missing from rpm Packages tab of Content View Version
  • BZ - 1914803 - Some of the "filters" permission changed after the upgrade.
  • BZ - 1915394 - [RFE] Adding an option to keep the ansible-runner files on Satellite.
  • BZ - 1919146 - [RFE] Possibility for further tailoring with Compliance Viewer role
  • BZ - 1920579 - The private bookmark status is not reflected correct in satellite GUI and we cannot make a private bookmark public through Red Hat Satellite GUI
  • BZ - 1922872 - Autosearch is not working even if its enabled.
  • BZ - 1923766 - Inconsistent time format on Sync Plans Details page
  • BZ - 1924625 - Sync status showing never synced even though the repositories has been synced successfully
  • BZ - 1927028 - CVE-2021-21290 netty: Information disclosure via the local system temporary directory
  • BZ - 1927532 - Large CRL file operation causes OOM error in Candlepin
  • BZ - 1931489 - Timeout to kill settings in job execution is not honored when running an Ansible playbook
  • BZ - 1937364 - CVE-2021-21295 netty: possible request smuggling in HTTP/2 due missing validation
  • BZ - 1937470 - hammer does not have a compute resource associate VMs command as web UI has
  • BZ - 1940308 - [BUG] The / at the end of proxy url is not being handled by satellite correctly when trying to enable repositories
  • BZ - 1942806 - AttributeError occured when run python 3 bootstrap.py on RHEL9.0 Alpha
  • BZ - 1944802 - [RFE] List of all Enabled Repository of all the content hosts using Reporting Templates.
  • BZ - 1944888 - CVE-2021-21409 netty: Request smuggling via content-length header
  • BZ - 1951626 - Validate Content Sync on bulk product produces error messages
  • BZ - 1955385 - Privilege escalation defined inside ansible playbook tasks is not working when executing the playbook via Remote Execution in Satellite 6
  • BZ - 1957070 - [RFE] add 'name' for the role filter in API
  • BZ - 1957288 - [RFE] Add option in the satellite to upload/sync OVAL defination to evalute the rule (xccdf_org.ssgproject.content_rule_security_patches_up_to_date) when performing Compliance scan on the client registered with the Satellite server.
  • BZ - 1958664 - [RFE]? Replace?bcrypt hash function with (FIPS-approved / NIST recommended) encryption algorithm for internal passwords?in the Satellite.
  • BZ - 1959691 - [Tuning] Tuning Puma in the predefined tuning profiles
  • BZ - 1960228 - Template is written twice when resolving provisioning templates for a host
  • BZ - 1962307 - CVE-2021-3200 libsolv: heap-based buffer overflow in testcase_read() in src/testcase.c
  • BZ - 1962410 - VMs Migrating are Losing ELS Subscriptions and Repos for RHEL 6
  • BZ - 1962847 - foreman-rake katello:* fails with the error message The Dynflow world was not initialized yet
  • BZ - 1964394 - Warning: postgresql.service changed on disk, when calling foreman-maintain service restart
  • BZ - 1965968 - Since Satellite 6.8 it's not possible to remove subscriptions from 'WebUI --> Content --> Subscriptions' page if the user doesn't have 'Setting' permissions.
  • BZ - 1967319 - The /api/usergroups/:usergroup_id/external_usergroups API is not accepting 1-group as the name of usergroup
  • BZ - 1968439 - CVE-2021-3584 foreman: Authenticate remote code execution through Sendmail configuration
  • BZ - 1969748 - Hammer documentation for "hammer organization create --help" command has unnecessary and repeated description
  • BZ - 1969992 - Exclude pulp-2to3-migration package from Satellite 7.0
  • BZ - 1970482 - Discovery plugin ignores IPv6 when doing reboot/kexec/fetch facts
  • BZ - 1972501 - After promoting the content view, Candlepin failed to mark the entitlement certificates as dirty
  • BZ - 1973146 - [RFE] As a user I want to receive an email notification when a job I triggered fails
  • BZ - 1974225 - Incremental CV update does not auto-publish CCV
  • BZ - 1975321 - select all button selects recommendation for other organizations which fails remediation action(JobInvocation).
  • BZ - 1978323 - [RFE]: Include curve25519sha256 support in Remote Execution
  • BZ - 1978689 - [global registration] [hammer] - No proper alignment in host-registration generate-command -h command
  • BZ - 1979092 - Capsule cname is reported as opposed to hostname
  • BZ - 1979907 - [RFE] IPv6 fact is not being parsed for satellite hosts.
  • BZ - 1980023 - satellite-installer times out during long running SQL DELETE transactions
  • BZ - 1980166 - Too many libvirt connections from Satellite due to ssh connection leaks
  • BZ - 1982970 - Fact updates causing unnecessary compliance recalculation in Candlepin
  • BZ - 1988370 - [RFE] Support Nutanix AHV in the Satellite virt-who plugin
  • BZ - 1992570 - Only Ansible config jobs should run in check mode
  • BZ - 1992624 - Remote Execution fails to honor remote_execution_connect_by_ip override on host
  • BZ - 1992698 - Store certain parts of dynflow data as msgpack
  • BZ - 1994212 - Failed at scanning for repository: undefined method `resolve_substitutions' for nil:NilClass
  • BZ - 1994237 - Executing any foreman-rake commands shows 'ErbParser' and 'RubyParser' are ignored.
  • BZ - 1994397 - Increased memory usage of pulp-3 workers during repo sync
  • BZ - 1994679 - Host - Last Checkin report template is not showing any other content host apart from Red Hat Satellite itself.
  • BZ - 1996803 - Grammatical errors with Insecure help text at Host Registration
  • BZ - 1997575 - Lifecycle Environment tab flash OSTree & Docker details for a second then shows actual content path.
  • BZ - 1997818 - "Login Page Footer Text" Blocking Login Button on Satellite UI
  • BZ - 1998172 - Puppet classes and environment importer. documentation opens in same tab instead of a new one
  • BZ - 1999604 - Unable to assign ansible roles to a host group via hammer/api with non-admin user
  • BZ - 2000699 - CVE-2021-33928 libsolv: heap-based buffer overflow in pool_installable() in src/repo.h
  • BZ - 2000703 - CVE-2021-33929 libsolv: heap-based buffer overflow in pool_disabled_solvable() in src/repo.h
  • BZ - 2000705 - CVE-2021-33930 libsolv: heap-based buffer overflow in pool_installable_whatprovides() in src/repo.h
  • BZ - 2000707 - CVE-2021-33938 libsolv: heap-based buffer overflow in prune_to_recommended() in src/policy.c
  • BZ - 2000769 - pulp3: CV publishes with dependency solving and same source repos for copy are not concurrent
  • BZ - 2002995 - hammer completion not working
  • BZ - 2004016 - httpboot not working on GRUB version provided by RHEL7
  • BZ - 2004158 - Sat 6.9.5: foreman-rake facts:clean aborts due to foreign key in database
  • BZ - 2004234 - [RFE] Email notification after a job template execution completes.
  • BZ - 2004335 - [RFE] API and Hammer functionality for Red Hat Access Insights in satellite 6
  • BZ - 2005072 - CVE-2021-32839 python-sqlparse: ReDoS via regular expression in StripComments filter
  • BZ - 2007655 - Authorization repository causing invalid upstream url
  • BZ - 2008809 - Task is failing but still showing success state
  • BZ - 2009049 - pulp_rpm: Basic-auth repository causing invalid upstream url
  • BZ - 2009398 - hammer host interface update does not update remote execution setting
  • BZ - 2010138 - Satellite doesn't forward the "If-Modified-Since" header for /accessible_content endpoint to Candlepin
  • BZ - 2011062 - cockpit webconsole login fails when remote execution configured for kerberos
  • BZ - 2013495 - CVE-2021-41136 rubygem-puma: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma
  • BZ - 2013503 - CVE-2021-30151 sidekiq: XSS via the queue name of the live-poll feature
  • BZ - 2013837 - Improve REX error reporting when uploading script
  • BZ - 2014037 - There is a new login account in satellite 6.9
  • BZ - 2014244 - Remove Greedy DepSolving from UI
  • BZ - 2014251 - Global Registration: Selecting Satellite URL as the proxy fails to register hosts with default config
  • BZ - 2018263 - Using Satellite with a proxy produces an SELinux alert
  • BZ - 2020329 - [RFE] Switch process output to DB
  • BZ - 2021255 - Satellite schedules one recurring InventorySync::Async::InventoryScheduledSync per org but each task syncs all orgs, resulting in harmless but unnecessary tasks
  • BZ - 2021352 - [RFE] One manifest version to cover all of Satellite 7
  • BZ - 2021406 - syncing tens of repos to capsule can cause deadlock: while updating tuple (...) in relation "core_content"
  • BZ - 2021985 - [BUG] Upgrading Satellite 6.9 with custom certificates to Satellite 6.10 beta will cause the same problem to occur as BZ# 1961886
  • BZ - 2022648 - please update to Satellite Ansible Collection 3.0.0
  • BZ - 2023809 - Satellite 6.10 upgrade fails with PG::NotNullViolation: ERROR: column "subscription_id" contains null values
  • BZ - 2024269 - Attempt of upgrading Satellite server to 6.7 or 6.8 stops with message "Please run 'foreman-maintain prep-6.10-upgrade' prior to upgrading." when using latest rubygem-foreman_maintain package
  • BZ - 2024553 - Repository sync jobs are failing with the Exception "NoMethodError undefined method `repository_href' for nil:NilClass" post upgrade to satellite version 6.10
  • BZ - 2024889 - Syncing RHEL 5 KS repository fails with: " Artifact() got an unexpected keyword argument 'sha' "
  • BZ - 2024894 - Unable to sync EPEL repositories on Satellite 6.10 when 'Mirror on Sync' is enabled
  • BZ - 2024963 - Syncing EPEL repos on Satellite 6.10 fails with: "Incoming and existing advisories have the same id but different timestamps and non-intersecting package lists.."
  • BZ - 2024978 - Satellite upgrade to 6.10.1 fails with multiple rubygem-sinatra package dependency errors
  • BZ - 2024986 - CV publish fails with: No route matches {:action=>"show", :controller=>"foreman_tasks/tasks", :id=>nil}, missing required keys: [:id] (ActionController::UrlGenerationError)
  • BZ - 2025049 - Executing remove-pulp2 after a successful Satellite 6.10 upgrade breaks synchronizations and repositories.
  • BZ - 2025437 - New OS created due to facts mismatch for operatingsystem for RHSM, Puppet and Ansible
  • BZ - 2025494 - Capsule sync task failed to refresh repo that doesn't have feed url with "bad argument (expected URI object or URI string)" error
  • BZ - 2025523 - Ansible roles are not starting automatically after provisioning
  • BZ - 2025760 - installer does not restart foreman.service when changing puma configuration
  • BZ - 2025811 - Upgrading to Satellite 6.9.6 and above introduces an increase in system memory consumption causing Pulp activities to fail with OOM at certain times
  • BZ - 2026239 - Config report upload failed with "No smart proxy server found on ["capsule.example.com"] and is not in trusted_hosts"
  • BZ - 2026277 - null value in column "manifest_id" violates not-null constraint error while syncing RHOSP container images
  • BZ - 2026415 - RFE: Add command for upgrading foreman-maintain to next major version
  • BZ - 2026658 - Fix name & path to OS host_init_config template
  • BZ - 2026718 - XCCDF Profile in Tailoring File selecting the first id not the selected id
  • BZ - 2026873 - Date parse error around SCA cert fetching when system locale is en_AU or en_CA
  • BZ - 2027052 - The redhat.satellite.foreman plugin is unable to collect all facts for the target systems as expected when using default api
  • BZ - 2027968 - A failed CV promote during publish or repo sync causes ISE
  • BZ - 2028178 - CVE-2021-44420 django: potential bypass of an upstream access control based on URL paths
  • BZ - 2028205 - db:seed can fail when there are host mismatches
  • BZ - 2028273 - Cannot pull container content - TypeError: wrong argument type String (expected OpenSSL/X509)
  • BZ - 2028377 - [RFE] add option to export and import just repository for hammer content-export
  • BZ - 2028446 - Pulp: Add options to change the import and export path in /etc/pulp/settings.py
  • BZ - 2028733 - katello-change-hostname fails to perform changes, leaving the system in an unusable state
  • BZ - 2029192 - Applying errata from the errata's page always tries to use katello-agent even when remote_execution_by_default set to true
  • BZ - 2029375 - webhook event "build_exited" never gets triggered
  • BZ - 2029385 - selinux denials when accessing /etc/pulp/certs/database_fields.symmetric.key
  • BZ - 2029548 - Excluding system facts logs as WARN causing log files to increase dramatically
  • BZ - 2029760 - Scenarios for Satellite and Capsule 7.0
  • BZ - 2029807 - foreman-maintain service fails for external postgres service, when no psql utility installed
  • BZ - 2029828 - TFTP Storage check fails on undefined method `[]' for nil:NilClass
  • BZ - 2029829 - change hostname tries to unconditionally restart puppetserver
  • BZ - 2029914 - FIPS enabled RHEL7 server: Candlepin services not running after installation
  • BZ - 2030101 - No longer be able to import content into disconnected Satellite for existing content views
  • BZ - 2030273 - The tasks generated by task export in html format are not sorted by date
  • BZ - 2030434 - Repository sync download all metadata files on every sync, even when there is no new packages
  • BZ - 2030460 - Need a way to sync from a specific content view lifecycle environment of the upstream organization
  • BZ - 2030715 - hammer content-[import,export] uses /tmp directory for temporary decompression location
  • BZ - 2031154 - After upgrading to Satellite 6.10, Repository sync randomly fails if a ReservedResource exists in core_taskreservedresource table of pulpcore DB.
  • BZ - 2031958 - CVE-2021-43797 netty: control chars in header names may lead to HTTP request smuggling
  • BZ - 2032098 - Incremental publish content view doesn't copy any contents
  • BZ - 2032400 - Remove warning from reports page in 7.0
  • BZ - 2032569 - CVE-2021-43818 python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through
  • BZ - 2032602 - Content not accessible after importing
  • BZ - 2032928 - Puppet disable command fails
  • BZ - 2032956 - Cannot create bookmark for credentials search
  • BZ - 2033174 - Large repo sync failed with "Katello::Errors::Pulp3Error: Response payload is not completed"
  • BZ - 2033201 - Button to assign roles on Host details page missing
  • BZ - 2033217 - "Cannot find rabl template 'api/v2/override_values/index'" error while trying to import Ansible variables using hammer CLI.
  • BZ - 2033336 - Add 'service restart' step in purge-puppet command
  • BZ - 2033560 - CVE-2021-42550 logback: remote code execution through JNDI call from within its configuration file
  • BZ - 2033593 - fact_values api performance issues when loading a large number of facts
  • BZ - 2033847 - Content view export failed with undefined method `first' for nil:NilClass
  • BZ - 2033853 - Publish content view failed with "PulpRpmClient::ApiError Error message: the server returns an error"
  • BZ - 2033940 - Error: AttributeError: 'NoneType' object has no attribute 'cast' thrown while listing repository versions
  • BZ - 2034317 - hammer repository upload-content with large file gives "Too many open files" error
  • BZ - 2034346 - CVE-2021-4142 Satellite: Allow unintended SCA certificate to authenticate Candlepin
  • BZ - 2034461 - Capsule failed to sync empty repositories
  • BZ - 2034552 - Puppet disable command fails on Capsule
  • BZ - 2034635 - New hosts UI, removal of Share your feedback link
  • BZ - 2034643 - New hosts UI, when navigated back to host detail from jobs detail, old ui is shown instead of new
  • BZ - 2034649 - New hosts UI, missing Ansible cards
  • BZ - 2034659 - OSTree repository update error: `excludes` is not a valid attribute in `PulpOstreeClient::OstreeOstreeRemote`
  • BZ - 2035195 - command "hammer full-help" gives error "Error: uninitialized constant HammerCLIForeman::CommandExtensions::PuppetEnvironment"
  • BZ - 2035204 - Tags need to be truncated in rh_cloud report
  • BZ - 2035480 - In Satellite upgrade, yum update failed to resolve the "createrepo_c-libs" dependency
  • BZ - 2035907 - Ansible config report time is one hour off
  • BZ - 2036054 - [Custom Certs] - Failed to install the custom certs on the Satellite 7.0.0 works fine in 6.10
  • BZ - 2036187 - self-upgrade fails with x.y should be greater than existing version x.y.z!
  • BZ - 2036381 - Applying exclude filter on a CV containing kickstart repos causes missing package groups
  • BZ - 2036628 - Rex job fails Error loading data from Capsule: NoMethodError - undefined method `each' for nil:NilClass
  • BZ - 2036721 - Satellite is creating the schedule on the wrong day of the week (day+1)
  • BZ - 2037024 - CVE-2021-45115 django: Denial-of-service possibility in UserAttributeSimilarityValidator
  • BZ - 2037025 - CVE-2021-45116 django: Potential information disclosure in dictsort template filter
  • BZ - 2037028 - CVE-2021-45452 django: Potential directory-traversal via Storage.save()
  • BZ - 2037180 - Failed to docker pull image with "Error: image <image name> not found" error
  • BZ - 2037275 - Cockpit integration always fails with authentication error
  • BZ - 2037508 - upload-content results in wrong RPM being added to product
  • BZ - 2037518 - The RSS channel is set to the upstream URL
  • BZ - 2037520 - Bootdisk new host page menu items are missing
  • BZ - 2037648 - upgrade check checking group ownership of /var/lib/pulp (pulp2) instead of /var/lib/pulp/content (pulp3)
  • BZ - 2037706 - Rex job fails: undefined method `join' for "RHSA-2012:0055":String
  • BZ - 2037773 - The new host detail page should be enabled by default without the experimental warning
  • BZ - 2038042 - Ansible Jobs are halting at status running
  • BZ - 2038192 - Upgrade to Satellite 6.10 fails at db:migrate stage if there are errata reference present for some ostree\puppet type repos
  • BZ - 2038241 - ERROR: at least one Erratum record has migrated_pulp3_href NULL value
  • BZ - 2038388 - Activation key issue with custom products on RHEL 6
  • BZ - 2038432 - Error when importing content and same package belongs to multiple repositories
  • BZ - 2038849 - repositories-setup procedure failing with "undefined method `map' for "*":String"
  • BZ - 2039289 - Installing Satellite7, satellite-installer runs redundant upgrade steps
  • BZ - 2039696 - Puppet-related hammer commands still missing after plugin enabled
  • BZ - 2040406 - Incorrect layout of new host details overview cards
  • BZ - 2040447 - [RFE] Katello host detail tabs should accept URL params for search
  • BZ - 2040453 - Limited CV docker tags cannot be pulled after syncing library repo with "limit sync tags"
  • BZ - 2040596 - undefined method `name' for "":String" on "All Hosts" page
  • BZ - 2040650 - Upgrade or offline backup fails on RHEL8 due to missing iptables command
  • BZ - 2040773 - Updating repo with GPG key ID fails
  • BZ - 2040796 - Grammar error on SyncPlan Details tab
  • BZ - 2040870 - Error to import rhel7 kickstart on disconnected satellite
  • BZ - 2041457 - Change ks= to inst.ks= and sendmac for RHEL 9 Beta
  • BZ - 2041497 - Incremental CV update fails with 400 HTTP error
  • BZ - 2041508 - Publication creation (during migration to pulp3 as well) can fail if /var/lib/pulp is NFS share
  • BZ - 2041551 - Puppet enable fails on RHEL8 due to missing package(s)
  • BZ - 2041588 - [RFE] Add Type to cdn configuration for 'disconnected' mode
  • BZ - 2041701 - Fail to import contents when the connected and disconnected Satellite have different product labels for the same product
  • BZ - 2042416 - Unclickable Class names in Configure > Puppet classes
  • BZ - 2042480 - Configure Cloud Connector fails after hostname change; potentially hits all templates
  • BZ - 2042848 - Package list of repository is empty page
  • BZ - 2042861 - [Recurring Logic]logging for recurring logic should be more verbose
  • BZ - 2043081 - 406 error appears when running insights-client --compliance
  • BZ - 2043097 - sql dump of dynflow data is encoded, what breaks sosreport
  • BZ - 2043144 - After upgrading to 6.10, Satellite fails to sync some repositories with large files with timeout error
  • BZ - 2043248 - Importing content fails if an importer with same name already exists
  • BZ - 2043501 - Satellite upgrade fails during db:seed with ActiveRecord::RecordNotDestroyed: Failed to destroy the record
  • BZ - 2043609 - pulpcore-workers grow very large when repositories have many changelog entries
  • BZ - 2043726 - content views configured as "import only" generate 404 errors during capsule sync
  • BZ - 2044581 - CVE-2022-23837 sidekiq: WebUI Denial of Service caused by number of days on graph
  • BZ - 2044606 - New version of Candlepin now has org in entitlement certificate and causes authorization issues
  • BZ - 2044631 - duplicate key value violates unique constraint "core_repositorycontent_repository_id_content_id_df902e11_uniq"
  • BZ - 2044839 - SSH Remote execution does not reap processes when closing multiplexed ssh connection
  • BZ - 2045504 - Show all provisioning templates by default
  • BZ - 2045854 - organization context fails to change in web UI
  • BZ - 2046281 - usability issues for user without execute_jobs_on_infrastructure_hosts permissions
  • BZ - 2046307 - New host details Errata overview card shows stale data for unregistered host
  • BZ - 2046322 - Manager role does contain the execute_jobs_on_infrastructure_hosts permission
  • BZ - 2046328 - Custom yum CV does not show correct list of packages
  • BZ - 2046337 - Certain manifest, subscription and repository related actions are broken while using HTTP Proxy as content_default_http_proxy in Satellite 6.10
  • BZ - 2046484 - RPM exclude filter does not work in web UI
  • BZ - 2046573 - update puppet classes via API to empty puppet classes does not update the classes
  • BZ - 2047285 - [RFE] enable redis cache for pulp content server by default
  • BZ - 2047443 - Unable to Import any content via Import/Export
  • BZ - 2047451 - [RFE] [SAT-4229] Packages - Filter by status
  • BZ - 2047485 - syncing repo using proxy can generate misleading log entries when proxy deny access to the url requested
  • BZ - 2047649 - please update to Satellite Ansible Collection 3.1.0
  • BZ - 2047675 - Getting "404 not found" when publishing a content view
  • BZ - 2047683 - Force cancel a paused task doesn't release the lock
  • BZ - 2048470 - Leapp upgrade fails after reboot with disabled postgresql redis tomcat services
  • BZ - 2048517 - service stop tries to execute CheckTftpStorage
  • BZ - 2048560 - REX doesn't honor effective_user when async_ssh is true
  • BZ - 2048775 - CVE-2022-22818 django: Possible XSS via '{% debug %}' template tag
  • BZ - 2048778 - CVE-2022-23833 django: Denial-of-service possibility in file uploads
  • BZ - 2048913 - "foreman-maintain health check --label check-hotfix-installed" fails with error "undefined method `[]' for nil:NilClass"
  • BZ - 2048927 - Satellite 6.10 clone is looking for mongo_data.tar.gz file
  • BZ - 2048986 - "foreman-maintain health check --label validate-yum-config" command failed with message "clean_requirements_on_remove=True Unset this configuration as it is risky while yum update or upgrade!"
  • BZ - 2049143 - Unable to run Convert2RHEL role on the host
  • BZ - 2049304 - katello-rhsm-consumer script subscription-manager version detection depends on subscription-manager rpm being installed
  • BZ - 2049799 - Incremental update with --propagate-all-composites makes new CVV but with no new content
  • BZ - 2049913 - Repo filtering shows all products and repos in different organizations
  • BZ - 2050100 - Module streams enabled by default are gone when CV starts using filters
  • BZ - 2050297 - Modifying 'Capsule tasks batch size for Ansible' causes subsequent Ansible jobs to hit TypeError
  • BZ - 2050323 - Misleading error message when incorrect org label is entered
  • BZ - 2050440 - pulp workers are idle despite there is one pending task
  • BZ - 2051374 - wrong sinatra obsoletes makes Satellite uninstallable
  • BZ - 2051408 - IP obfuscation algorithm can generate invalid IPs
  • BZ - 2051468 - Active directory users taking too much time to login when its part of many groups.
  • BZ - 2051522 - pulpcore_t and pulpcore_server_t domains are prevented to access httpd_config_t files
  • BZ - 2051543 - smart_proxy_remote_execution_ssh leaves zombie ssh processes around
  • BZ - 2051912 - Some of the services failed to start after satellite restore
  • BZ - 2052048 - Repeated Ansible Role run scheduling adds extra time to specified start date
  • BZ - 2052088 - Satellite-installer does not ensure proper permissions on /etc/foreman-proxy/ssl_ca.pem at every run
  • BZ - 2052420 - Satellite upgrade fails during db:migrate with PG::DuplicateTable: ERROR: relation "index_hostgroups_puppetclasses_on_hostgroup_id" already exists
  • BZ - 2052493 - restore on another machine fails with ERROR: web server's SSL certificate generation/signing failed
  • BZ - 2052506 - "foreman-maintain health check --label check-hotfix-installed" does not display the modified files in command stdout.
  • BZ - 2052524 - rubygem-sinatra el8 rpm should keep the epoch number
  • BZ - 2052815 - dynflow fails with "403 extra bytes after the deserialized object"
  • BZ - 2052958 - Job invocation fails for errata installation.
  • BZ - 2053329 - content-view import fails with Error: PG::StringDataRightTruncation: ERROR: value too long for type character varying(255)
  • BZ - 2053395 - Satellite upgrade failed with error "Couldn't connect to the server: undefined method `to_sym' for nil:NilClass"
  • BZ - 2053478 - Uploading external DISA SCAP content to satellite 6.10 fails with exception "Invalid SCAP file type"
  • BZ - 2053601 - Errata icons are the wrong colors
  • BZ - 2053839 - Deletion of Custom repo fails with error "uninitialized constant Actions::Foreman::Exception" in Satellite 7.0
  • BZ - 2053843 - hammer shell with redirected input prints stty error on RHEL8
  • BZ - 2053872 - Changing Upstream URL of a custom repo in WebUI raises error "Upstream password requires upstream username be set."
  • BZ - 2053876 - Multiple instances of scheduled tasks of more types
  • BZ - 2053884 - Host detail UI setting is not honored when returning to the host page after canceling an Edit action
  • BZ - 2053923 - InsightsScheduledSync raises exception when allow_auto_insights_sync is false
  • BZ - 2053928 - Satellite UI suddenly shows "Connection refused - connect(2) for 10.74.xxx.yyy:443 (Errno::ECONNREFUSED) Plus 6 more errors" for a capsule even if there are no connectivity issue present in Satellite\Capsule 7.0
  • BZ - 2053956 - Installing Satellite 7.0 on FIPS enabled RHEL 8.5 fails on "katello-ssl-tool --gen-ca" step with error "ERROR: Certificate Authority private SSL key generation failed"
  • BZ - 2053970 - Upgrade to Red Hat Satellite 7.0 fails at db:migrate step with error "undefined local variable or method `type' for #<Katello::CdnConfiguration:0x00000000153c6198>"
  • BZ - 2053996 - ReclaimSpace does not acquire repo lock so it can be run concurrently with the repo sync
  • BZ - 2053997 - hammer lacks command "repository reclaim-space"
  • BZ - 2054008 - Retain packages on Repository does not synchronize the specified number of packages on Satellite 7
  • BZ - 2054121 - API and WebUI must disallow repo create with negative Retain package versions count
  • BZ - 2054123 - hammer repository create ignores --retain-package-versions-count option
  • BZ - 2054165 - After satellite-change-hostname, foreman tasks acquired lock error still refers to URL of old hostname
  • BZ - 2054174 - Repo discovery feature cannot discover yum repositories because 'Content Default HTTP Proxy' is not used to connect to the upstream URL in Satellite 7.0
  • BZ - 2054182 - remove pulp2 automatically on upgrade to 6.11 (If the user hasn't already done it)
  • BZ - 2054211 - CVE-2022-23634 rubygem-puma: rubygem-rails: information leak between requests
  • BZ - 2054340 - [SAT-4229] Module streams - basic table
  • BZ - 2054758 - Satellite 6.10 clone is failing with user pulp doesn't exist
  • BZ - 2054849 - CDN loading error for non-admin user and non-default org
  • BZ - 2054971 - Enable registration by default
  • BZ - 2055159 - Satellite/capsule 6.10 and tools 6.10 repos are listed in the Recommended Repositories for Sat 7.0
  • BZ - 2055312 - Enabling ISO type repository fails with PG::NotNullViolation: ERROR
  • BZ - 2055329 - Cannot import a cv
  • BZ - 2055495 - If Kickstart 7.X repos are being synced to Capsule 7.0 then Pulp 3 tries to sync a non-existant HighAvailability and ResilientStorage repo as well and gets 404 fnot found
  • BZ - 2055513 - Deletion of Custom repo deletes it from all versions of CV where it is included but the behavior is different for Red Hat based repos in Satellite 7.0
  • BZ - 2055570 - Add check for LCE and CV presence in upstream server for disconnected Satellite
  • BZ - 2055808 - Upgrading the Satellite 7.0 from Snap 8 to Snap 9 , sets the CDN configuration for all Organizations in airgapped mode
  • BZ - 2055951 - Index content is creating duplicated errata in "katello_erratum" table after upgrading to Satellite 6.10
  • BZ - 2056167 - [RFE] Create new content view should redirect to "Repositories" and not "Versions" tab
  • BZ - 2056171 - [RFE] Publish new version should redirect to "Version" tab
  • BZ - 2056172 - [RFE] Add repositories button should highlight in Content view
  • BZ - 2056173 - [RFE] Content view filter doesn't shows "Start Date" & "End Date" tags to confirm the correct user inputs.
  • BZ - 2056177 - [Bug] Custom subscriptions consumed and available quantity not correct in the CSV file
  • BZ - 2056178 - [RFE] Add RHEL-8 EUS repositories under recommended repositories
  • BZ - 2056183 - Content view filter should suggest architectures parameters in RPM rule
  • BZ - 2056186 - After enabling the Red Hat web console feature in Satellite 7.0, the redesigned Host page does not offers any option to connect to the Web\Cockpit Console of the client system
  • BZ - 2056189 - Remove RHEL 7 EUS repository from the Recommended Repositories list
  • BZ - 2056198 - [RFE] "Add Content Views" button should highlight in Composite Content view
  • BZ - 2056202 - [RFE] Promote button should be displayed in the Content view version
  • BZ - 2056237 - [Bug] Satellite Administration Documentation is missing
  • BZ - 2056469 - Not possible to set hostgroup parameter during hostgroup creation
  • BZ - 2056657 - Add deprecation banners for traditional (non-SCA) subscription management
  • BZ - 2056966 - Part of REX job fails if multiple capsules are used for the job
  • BZ - 2057178 - CVE-2021-44568 libsolv: heap-overflows in resolve_dependencies function
  • BZ - 2057309 - Latest Hardware version for VMware vSphere 7.0U3 is not available on Satellite 7
  • BZ - 2057416 - rubygem-rack is obsoleted without epoch
  • BZ - 2057605 - foreman.rpm pulls in nodejs
  • BZ - 2057632 - Creating repo fails if there's a validation error in the first save.
  • BZ - 2057658 - Update pulp-rpm to 3.17
  • BZ - 2057782 - Limit sync tags parameter is displayed twice on the repositories detail page
  • BZ - 2057848 - Inclusion of tags in limit sync tags parameter is not white listing the tags to sync
  • BZ - 2058397 - Ensure pulp-rpm 3.17 is built for Satellite 6.11
  • BZ - 2058532 - certs-regenerate breaks qpidd certificates, resulting in qpidd start-up failures: Couldn't find any network address to listen to
  • BZ - 2058649 - Unable to set or unset "Discovery location" settings from UI of Satellite 7.0 but the same is partly feasible via hammer_cli.
  • BZ - 2058711 - Ostree type is missing during repo creation.
  • BZ - 2058844 - The foreman-protector plugin does not works for Satellite 6.11 if the OS is RHEL 8
  • BZ - 2058863 - Everytime a host build is being submitted that somehow generates a huge traceback with error "undefined method `insights' for nil:NilClass" in Satellite 7.0
  • BZ - 2058867 - The insights registration steps happens during host build even if the host_registration_insights parameter is set to false in Satellite 7.0
  • BZ - 2058894 - Server fingerprints not managed properly
  • BZ - 2058905 - Content Import does not delete version on failure
  • BZ - 2058984 - The Satellite 7.0 beta offers the download capability of both Host and Full Host image via UI where as the support for Host image was already removed in Satellite 6.10
  • BZ - 2059576 - non admin user with host_view permission is unable to look at old host details ui
  • BZ - 2059985 - please update to Satellite Ansible Collection 3.3.0
  • BZ - 2060097 - [RFE] ouia-ID for content view table
  • BZ - 2060396 - satellite-maintain self-upgrade passes even if the next major version maintenance repository isn't available
  • BZ - 2060512 - Update terminology for ISS
  • BZ - 2060546 - Leapp-upgrade package installation failing with dependency on sat 7.0
  • BZ - 2060885 - Update foreman-ansible package to 7.0.3
  • BZ - 2061688 - old rubygems (from 6.7 and older) installed and prevent EL7 to EL8 upgrade
  • BZ - 2061749 - Templates sync with git on RHEL8 is causing SElinux error
  • BZ - 2061773 - Settings defined by DSL are not properly encrypted
  • BZ - 2061970 - Mirror on sync still shows up in 'hammer repository info', while mirroring policy does not
  • BZ - 2062189 - satellite-installer gets failed with "Could not open SSL root certificate file /root/.postgresql/root.crt" error.
  • BZ - 2062476 - GPG shows blank on repo details page render, but is correct when selecting the dropdown
  • BZ - 2063149 - CVE-2022-23633 rubygem-actionpack: information leak between requests
  • BZ - 2063190 - Upgrading from Satellite 6.9 to Satellite 6.10.3 fails with error "undefined method operatingsystems' for nil:NilClass" during the db:migrate step
  • BZ - 2063575 - [RFE] - add ouia-ID for buttons on a cv
  • BZ - 2063910 - LEAPP upgrade fails with [Errno 2] No such file or directory: '/var/lib/leapp/scratch/mounts/root_/system_overlay/etc/pki/pulp/content/pulp-global-repo.ca'
  • BZ - 2064400 - Migration of encrypted fields between 3.14 and 3.16 is broken for some remotes
  • BZ - 2064410 - Incorrect file permissions in /var/lib/pulp/media/... lead to repository sync errors
  • BZ - 2064434 - Repository set not showing repos after importing library and creating an ak in a disconnected satellite
  • BZ - 2064583 - High memory usage of foreman-proxy during a scaled bulk REX job
  • BZ - 2064707 - bootstrap.py can't reach the API via the capsule
  • BZ - 2064793 - Remotes should have username and password cleared out if a user sets them to be blank
  • BZ - 2065015 - "Sync Connect Timeout" settings takes invalid value and shows update successful but doesn't reflect the change for invalid values
  • BZ - 2065027 - Job invocation installs all the installable errata if incorrect `Job Template` is used.
  • BZ - 2065391 - LCE and content view label resets when trying to delete the field names in "Upstream Foreman Server" tab
  • BZ - 2065448 - [RFE] - add ouia-ID prop to update buttons in CDN configuration
  • BZ - 2065450 - [RFE] - add ouia-ID prop to all fields in CDN configuration
  • BZ - 2066408 - REX SSH Key works for SSH but fails for REX on RHEL 8.5 Host
  • BZ - 2066899 - After IP change on Tues Mar 22 Satellite manifest tasks fail with 'could not initialize proxy [org.candlepin.model.UpstreamConsumer#XXXXX] - no Session'
  • BZ - 2067301 - hammer content-import fails with error Export version 3.14.9 of pulpcore does not match installed version 3.14.12 if the z-stream versions are different for the connected and disconnected satellite 6.10
  • BZ - 2067331 - Upgrade to Satellite 6.9 and 6.10 fails with error "ActiveRecord::RecordInvalid: Validation failed: Remote execution features is invalid" during db:seed stage
  • BZ - 2069135 - After restore from 6.10.2 (and older) backup to 6.10.3 candlepin is broken
  • BZ - 2069248 - documentation links in 6.11 navigate to 7.0 instead of 6.11
  • BZ - 2069381 - new host ui, do not navigate to task, instead navigate to job
  • BZ - 2069456 - new host ui details,ansible roles, bug when all ansible roles are assigned
  • BZ - 2069459 - new host ui details, edit ansible roles, when assigned, wait and not confirmed, role is unasigned automatically
  • BZ - 2069640 - insights total risk chart network errors in new host page's overview tab
  • BZ - 2070176 - Clicking on "Select recommendations from all pages" of host details page(insights tab) selects insights recommendations of other hosts as well.
  • BZ - 2070177 - De-duplicate errata migration doesn't delete child records
  • BZ - 2070242 - The satellite-maintain change with respect to 6.11 version shift
  • BZ - 2070272 - Sync Status page does not show syncing progress bar under "Result" column when syncing a repo
  • BZ - 2070620 - After upgrading to 6.11 ping check fails with "Some components are failing: katello_agent"
  • BZ - 2072447 - CVE-2022-28346 Django: SQL injection in QuerySet.annotate(),aggregate() and extra()
  • BZ - 2072459 - CVE-2022-28347 Django: SQL injection via QuerySet.explain(options) on PostgreSQL
  • BZ - 2072530 - Improvements on foreman-maintain's self-upgrade mechanism
  • BZ - 2073039 - LEAPP upgrade enables wrong repositories for capsules
  • BZ - 2073124 - HTTP responses include incorrect ETag value
  • BZ - 2073194 - Filter API/ UI doesn't return errata, package group, module stream filter rules if repository has been removed from CV
  • BZ - 2073307 - "Selected scenario is DISABLED" errors when trying to upgrade installer packages
  • BZ - 2073313 - "Publish" action in the drop down doesn't work
  • BZ - 2073421 - The new host page should be disabled by default
  • BZ - 2073468 - Bootdisk Provisioning Templates are missing description
  • BZ - 2073469 - Discovery kexec Provisioning Template is missing description
  • BZ - 2073470 - "Kickstart default user data" Provisioning Template contains doubled description key
  • BZ - 2075434 - bootstrap.py fails if puppet is not enabled in Satellite
  • BZ - 2075519 - Upgrade fails during db:migrate with PG::ForeignKeyViolation: ERROR: update or delete on table "katello_errata" violates foreign key constraint "katello_content_facet_errata_errata_id"
  • BZ - 2075528 - OS upgrade keeps original TFTP setup preventing machines to boot from the network
  • BZ - 2076372 - Address VCR test changes in pulp_rpm_client 3.17.5
  • BZ - 2076684 - NullPointerException during manifest refresh
  • BZ - 2076987 - After upgrade any foreman-rake command shows 'ErbParser' and 'RubyParser' are ignored.
  • BZ - 2077850 - Puppet purge fails on an upgraded Satellite
  • BZ - 2078983 - Tabbable latest version 5.3.1 is not compatible with jest dom/ JSDom without changes to PF4.
  • BZ - 2079357 - foreman-maintain maintenance-mode status command fails with `undefined method `maintenance_mode_status?' for nil:NilClass`
  • BZ - 2080909 - The satellite-maintain self-upgrade does not disable the non RHSM repository if it was not enabled on system
  • BZ - 2081280 - Bootdisks are left in privatetmp of httpd
  • BZ - 2081459 - Omit python*-pulp-ostree packages
  • BZ - 2082076 - Settings - Like operator for name
  • BZ - 2082241 - hammer host-collection create fails with "Too many arguments" when setting unlimited-hosts
  • BZ - 2082505 - Omit python*-pulp-python packages
  • BZ - 2082560 - satellite-clone missed version rename 7.0 to 6.11
  • BZ - 2083532 - PG::ForeignKeyViolation: ERROR: update or delete on table "katello_erratum_packages" violates foreign key constraint "katello_msep_erratum_package_id_fk" on table "katello_module_stream_erratum_packages"
  • BZ - 2084106 - satellite-change-hostname on capsule runs deprecated capsule-installer
  • BZ - 2084624 - Unable to install 6.11 with ansible-core 2.12
  • BZ - 2085446 - LEAPP preupgrade --target 8.6 fails to resolve conflicts for rubygem-openscap
  • BZ - 2085528 - Change "Component content view" to "Content view"
  • BZ - 2086101 - rhel8 repos are missing python2-qpid, making qpid-tools and thus the katello-agent support unavailable
  • BZ - 2086683 - Actions::Candlepin::Owner::Import failing with "Entity version collision detected"
  • BZ - 2086948 - Remove 6.11 beta branding
  • BZ - 2087727 - Upgrade to Satellite 6.10.5.1 fails with error message "PG::NotNullViolation: ERROR: null value in column "erratum_package_id" violates not-null constraint"
  • BZ - 2089361 - satellite-clone is broken on RHEL8.6
  • BZ - 2089794 - Insights recommendations get halted with error undefined method `id' for nil:NilClass
  • BZ - 2089796 - Absence of Package redhat-access-insights-puppet.noarch in rhel 8 sat/capsule
  • BZ - 2089812 - Need to list Satellite Utils and Puppet agent repositories on Recommended Repositories page for Sat 6.11
  • BZ - 2089928 - Dependency Issue when attempting to enable Satellite Infoblox DNS and DHCP plugins on RHEL 8
  • BZ - 2090740 - Update links for the new puppet documentation
  • BZ - 2090820 - satellite upgrade to 6.11 fails in installer with "Could not open SSL root certificate file /root/.postgresql/root.crt" error for external DB setup
  • BZ - 2093679 - satellite-installer --enable-foreman-proxy-plugin-shellhooks fails with error Error: Unable to find a match: rubygem-smart_proxy_shellhooks in Red Hat Satellite 6.11
  • BZ - 2094255 - Configure Cloud Connector runs against an old hostname after a hostname change
  • BZ - 2094280 - rhc_instance_id is not being set correctly by configure cloud connector playbook.
  • BZ - 2094454 - Error "missing keywords: :arch, :major, :minor" on CDN configuration
  • BZ - 2095598 - The completion of a remediation playbook should indicate success or failure combined for all hosts in the run
  • BZ - 2095599 - Satellite yggdrasil-forwarder-worker does not send proper lowercase JSON to RHC API
  • BZ - 2096198 - Too many connection issue occurring for on-demand content sync
  • BZ - 2096921 - "Reconfigure Cloud Connector" job fails on upgraded Satellite configured with fifi/receptor.