Important: Satellite 6.12 Release

Synopsis

Important: Satellite 6.12 Release

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat Satellite 6.12. The release contains a new version of Satellite and important security fixes for various components.

Description

Red Hat Satellite is a systems management tool for Linux-based
infrastructure. It allows for provisioning, remote management, and
monitoring of multiple Linux deployments with a single centralized tool.

Security Fix(es):

  • netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data (CVE-2021-37136)
  • netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way (CVE-2021-37137)
  • python3-django: Possible XSS via template tag (CVE-2022-22818)
  • tfm-rubygem-nokogiri: ReDoS in HTML encoding detection (CVE-2022-24836)
  • tfm-rubygem-sinatra: Path traversal possible outside of public_dir when serving static files (CVE-2022-29970)
  • tfm-rubygem-git: Package vulnerable to Command Injection via git argument injection (CVE-2022-25648)
  • rubygem-rails-html-sanitizer: Possible XSS with certain configurations (CVE-2022-32209)
  • python3-django: Potential SQL injection via Trunc and Extract arguments (CVE-2022-34265)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

The items above are not a complete list of changes. This update also fixes
several bugs and adds various enhancements. Documentation for these changes
is available from the Release Notes document.

Solution

For Red Hat Satellite 6.12, see the following documentation for the release.
https://access.redhat.com/documentation/en-us/red_hat_satellite/6.12

The important instructions on how to upgrade are available below.
https://access.redhat.com/documentation/en-us/red_hat_satellite/6.12/html/upgrading_and_updating_red_hat_satellite

Fixes

  • BZ - 1309740 - [RFE] As a user, I want to schedule a job and receive an e-mail summary when it completes
  • BZ - 1703496 - Satellite audits cleanup
  • BZ - 1732590 - Cannot add filter on same RPM name with different architectures
  • BZ - 1775813 - A publish content view displays (Invalid Date) for the date and time of when the content view was published.
  • BZ - 1829468 - [RFE] Be able to retrieve the software vendor package from the installed package
  • BZ - 1830968 - [RFE] API should return simple results to understand if the repositories for hosts are enabled or not.
  • BZ - 1834897 - [RFE] Remove the configuration 'env=Library' created by the virt-who configuration plugin in the Satellite WebUI
  • BZ - 1850393 - [RFE] REX Pull Provider
  • BZ - 1868175 - Red Hat Satellite should notify about published content view while removing Lifecycle environment
  • BZ - 1868323 - "Confirm services restart" modal window grammatically does not respect that multiple systems are selected for a reboot
  • BZ - 1870816 - Deploy script breaks when the password of hypervisor contains single quotes
  • BZ - 1879811 - [ALL_LANG] [SAT_6.8 | 6.9 | 6.10|6.11 ] Web elements are not localized (Available Button, ON/OFF Switch Button)
  • BZ - 1884148 - description of filter_host_parents does not match virt-who-config
  • BZ - 1892218 - Multi-page listing when adding repositories to Content Views confuses the number of repositories to add
  • BZ - 1892752 - Scheduled job "Create RSS notifications" does not use proxy
  • BZ - 1894033 - [RFE] Add SSH User field to Advanced Fields in Job Invocation of SSH Command - remote_execution_ssh_user per Remote Execution task
  • BZ - 1908841 - Capsule certs regeneration fails with an error if the organization has a `'` in the name
  • BZ - 1912941 - Verbose log outputs for Ansible jobs are reported to all Hosts present on the Job.
  • BZ - 1925165 - [RFE] Unordered RPMs in repodata decrease compression efficiency
  • BZ - 1930577 - when running ReX via SSH on 2242 hosts, got "Timed out reading data from server"
  • BZ - 1931532 - When running remote execution from Satellite to an RHEL 8 with tlog enabled it fails.
  • BZ - 1931665 - Need clearer error message when manifest is no longer valid when syncing inventory
  • BZ - 1934210 - Bad HTTP method requests filling up /var/log/messages with stack traces
  • BZ - 1938092 - [RFE] Insights recommendations should have url links for related knowledgebase article and c.r.c.
  • BZ - 1940396 - [RFE] Introduction of GUI based option to be able to bulk select and remove Content View versions in Red Hat Satellite 6
  • BZ - 1951542 - Insights Table doesnt translate the pagination strings
  • BZ - 1952939 - [RFE] Support for Satellite Tools version-1 repository is version.
  • BZ - 1959136 - Backtick in password causes failure during deployment of virt-who config.
  • BZ - 1962253 - Global registration succeeded but throwing error messages when auto-attach is true
  • BZ - 1964080 - [BUG] The != and ~ search params does not work with os_minor parameter in Satellite 6.9
  • BZ - 1970132 - [BUG] Invalid choice for template_kind listed for os_default_template module
  • BZ - 1970623 - [BUG] Error Can't join 'Katello::ContentFacetRepository' to association named 'hostgroup' when clicking on "Errata Installation" inside a host_collection as a non-admin user
  • BZ - 1971747 - "Registered Content Hosts" Report is Showing the Wrong Available Kernel Version for RHEL 7.7 Client
  • BZ - 1973329 - Provide upstream repository name value to allow a name change on the repository to not break Satellite if an enabled repository's name gets changed
  • BZ - 1974180 - Default user input value is not set for job invocation
  • BZ - 1981444 - "Subscription - Entitlement Report" does not show correct number of subscriptions attached/consumed
  • BZ - 1982698 - Ansible playbook execution crash for Hosts: localhost
  • BZ - 1982745 - Reprovisioning a host using new HostGroup does not inherit root password from the new HostGroup
  • BZ - 1984400 - Capsule upgrade/install fails due to proxy configuration in 'HTTP(S) proxy' in settings
  • BZ - 1989631 - Ruby warning: URI.escape is obsolete after the host is provisioned
  • BZ - 1990119 - Documentation bug for the compute_resource module
  • BZ - 1991557 - Many Postgres ERRORs (duplicate key) especially on RedHat repo sync
  • BZ - 1994877 - [RFE] Example is missing in "Install packages" option in the Advanced Tab of "Register Host" form.
  • BZ - 1994945 - hammer cannot use the cluster name or id as valid input when clusters are residing inside folders and fails with error Fog::Vsphere::Compute::NotFound error
  • BZ - 1998477 - Add Simple content access status API to check whether SCA is enabled or disabled in Satellite
  • BZ - 2000613 - The login page exposes version of the satellite
  • BZ - 2001517 - [RFE] Allow "on_demand" download policy for repositories of content_type docker
  • BZ - 2001552 - Host facts are not uploaded to satellite when content host is registered with Satellite using global registration form.
  • BZ - 2004133 - CVE-2021-37136 netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data
  • BZ - 2004135 - CVE-2021-37137 netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way
  • BZ - 2006974 - [ALL_LANG] [SAT_6.10 | 6.11] 'No matches found' text is untranslated in search bar
  • BZ - 2007117 - [ ALL_LANG] [SAT_6.10 | 6.11] 'Filter' string from switcher section search box is not marked as translatable string
  • BZ - 2011312 - Misspelled word in tooltip "Toggel" instead of "Toggle"
  • BZ - 2013611 - Hammer compute-profile create missing 'boot_order' from 'compute-attributes'
  • BZ - 2015062 - Scap Content Page redirects to Satellite documentation instead of Scap Content
  • BZ - 2015757 - 'Mail enabled' setting cannot be switched with the hammer user command.
  • BZ - 2016924 - The value set by 'hammer activation-key content-override'command cannot be confirmed by 'hammer activation-key info' command.
  • BZ - 2022065 - ansible modules don't work correctly when a HTTP?HTTPS redirect occurs
  • BZ - 2022649 - Hammer unable to send correct value for for Job Templates in order to update ALL packages.
  • BZ - 2024175 - [RFE] Include Tower extra vars feature when calling the API callback
  • BZ - 2024576 - Extra audit record created on Organization create action
  • BZ - 2024968 - [RFE] Expose parameter trusted_proxies on satellite-installer
  • BZ - 2025892 - [RFE] Allow configuring cockpit with multiple origins through satellite-installer
  • BZ - 2025926 - [RFE] Identify host Build Token using hammer
  • BZ - 2027947 - HypervisorHeartbeatUpdateJob is taking long time to process and updates wrong consumer records
  • BZ - 2028112 - Ansible roles are failed with exit status 0 but the job is showing status success and the task is also showing result success.
  • BZ - 2033321 - Manifest refresh fails on Candlepin: One or more pools was left in an undefined state
  • BZ - 2033381 - Remove the space at the end of foreman-proxy-certs-generate printed installer cmd
  • BZ - 2035287 - The online backup attempt still shows a warning about mongodb when executed in Satellite 6.10
  • BZ - 2036151 - Can't assign different networks on 2+ NICs with vNIC profiles selected
  • BZ - 2038989 - [RFE] Satellite Security Concerns for Apache
  • BZ - 2043126 - Non-enabled repository types make it into the apipie help-text
  • BZ - 2043242 - [RFE] make worker show what task they are currently running
  • BZ - 2048547 - When using async_ssh true and for some reason the script retrieve.sh fails to, the task remain stuck
  • BZ - 2048775 - CVE-2022-22818 django: Possible XSS via '{% debug %}' template tag
  • BZ - 2049595 - missing information about puppet attributes in API/CLI
  • BZ - 2051648 - [RFE] Better Detail When Job Fails Due To SSH Problem
  • BZ - 2051891 - vCPUs in RHV getting reset to one vCPU after editing a host in Satellite
  • BZ - 2052076 - foreman-proxy does not log permissions errors when trying to read ssl_ca.pem
  • BZ - 2053842 - The "Serve via HTTP" and "Verify SSL" options in Repo Discovery page does not functions at all in Satellite 7.0
  • BZ - 2054011 - Submit button on Edit page of a host will revert back to a invalid page on Satellite
  • BZ - 2054042 - [RFE] Logs in dynflow console needs more descriptive when SSH REX job fails on Satellite 7.
  • BZ - 2054786 - {"publication":["Invalid hyperlink - Object does not exist."]} error when syncing a repository
  • BZ - 2054969 - Navigation switch between multiple capsules don't work as expected
  • BZ - 2055391 - After upgrade products with repositories that had Ignorable Content = drpm can no longer be modified
  • BZ - 2055416 - redhat.satellite.content_upload ansible module with unexpected src parameter behavior
  • BZ - 2055979 - [RFE] - use native Ansible module for Install from git job template
  • BZ - 2056188 - The redesigned Host page in Satellite does not offers any option to invoke/schedule a remote execution job for a client system
  • BZ - 2056702 - Import library with overlapping content can fail with unique-constraint violation
  • BZ - 2058037 - UEFI: Grub network boot templates need to be updated
  • BZ - 2059179 - job template selector missing id in the new rex wizard
  • BZ - 2060651 - Cannot upload a package to a repository if the same package already exists in another repository, but is not downloaded
  • BZ - 2062800 - OpenSCAP is using the removed puppetrun setting
  • BZ - 2064979 - Clients can't subscribe to or enable Red Hat repositories after renewing subscriptions
  • BZ - 2068454 - repositories/import_uploads API endpoint do require two mandatory parameters
  • BZ - 2069306 - [RFE] Need syncable yum-format repository exports
  • BZ - 2069440 - [RFE] new host ui details, upgrades to host status
  • BZ - 2069634 - new host ui details, unable to read the host from different taxonomies when logged in
  • BZ - 2070001 - Space reclaiming fails on a blank Satellite
  • BZ - 2070535 - Content View publish fails with error PG::CardinalityViolation: ERROR: ON CONFLICT DO UPDATE command cannot affect row a second time.
  • BZ - 2070732 - Use more accurate messaging when host statuses are cleared
  • BZ - 2070972 - Sentence case fixes needed in the new Host page
  • BZ - 2072696 - Creating ESX compute resource on vcenter 7.x fails with InvalidArgument: A specified parameter was not correct: deviceChange[1].device.key
  • BZ - 2073305 - installer spams with katello-certs-check output when using custom certs
  • BZ - 2074346 - CVE-2022-24836 nokogiri: ReDoS in HTML encoding detection
  • BZ - 2075056 - new host ui details, repository sets, search auto-complete is missing
  • BZ - 2076843 - CVE-2022-25648 ruby-git: package vulnerable to Command Injection via git argument injection
  • BZ - 2077811 - new host ui, content, errata subtab, when N/A is chosen as severity filter erratas results are empty
  • BZ - 2077822 - new host ui details, add button to navigate to old content UI
  • BZ - 2077824 - [RFE] API to allow search by object ID on any object
  • BZ - 2080324 - Satellite incorrectly reports email test success
  • BZ - 2080423 - Docker pull fails with 'missing or empty Content-Length header'
  • BZ - 2081096 - CVE-2022-29970 sinatra: path traversal possible outside of public_dir when serving static files
  • BZ - 2084130 - CertificateCleanupJob fails with foreign key constraint violation on table cp_upstream_consumer
  • BZ - 2085490 - Discovery and bootdisk templates don't get description populated from metadata
  • BZ - 2088303 - Webhook raises "certificate verify failed" error even the target host is trusted by the system SSL CA bundle
  • BZ - 2089445 - The About page under Administer still refers to IRC channel at Freenode
  • BZ - 2089828 - default Organization and location not set for AD users
  • BZ - 2091044 - new host ui details,ansible roles, submitting form without any roles should show warning
  • BZ - 2092039 - Content import fails if repo labels differ and repo is already imported
  • BZ - 2093884 - Every CV Publish+Promote action followed by an automated Capsule sync task generates a huge traceback "(ActiveRecord::RecordNotFound): Couldn't find ForemanTasks::Task::DynflowTask" in Satellite 6.11
  • BZ - 2094019 - Missing LCE and CV label in CLI CDN configuration
  • BZ - 2095187 - Fail to create virtwho config on nutanix env for error "Invalid option for hypervisor [ahv]"
  • BZ - 2095820 - All errata are applied when user only selects certain errata
  • BZ - 2096429 - Global Registration will fail if use a different language
  • BZ - 2098240 - [RFE] Add 'System purpose' card to new host details / Overview tab
  • BZ - 2099620 - Starting or Restarting foreman.socket will raise a harmless "TCP_NODELAY failed: Operation not supported" error in Red Hat Satellite 6.9/6.10/6.11
  • BZ - 2100578 - satellite-clone should enable the Satellite module
  • BZ - 2100887 - Repository sets and Errata tabs do not show toggle group when host is in Library environment but non-default content view
  • BZ - 2101579 - Retain packages on Repository removes RPMs from Pulp but not from Katello
  • BZ - 2101882 - CVE-2022-32209 rubygem-rails-html-sanitizer: possible xss with certain configurations
  • BZ - 2101986 - Getting "NoPermission: Permission to perform this operation was denied." when edit host or compute profile
  • BZ - 2102145 - 'Satellite-maintain backup online' states info about Mongo in the warning message
  • BZ - 2102456 - [RFE] - Add static ouia-id to modal with wizard for publishing a cv
  • BZ - 2102825 - satellite-clone fails to adjust ownership of /var/lib/pulp if it's owned by non-existing user/group
  • BZ - 2102867 - Post upgrade to satellite 6.10, sync summary email notification shows the incorrect summary for newly added errata.
  • BZ - 2102896 - CVE-2022-34265 python-django: Potential SQL injection via Trunc(kind) and Extract(lookup_name) arguments
  • BZ - 2103096 - After syncing a repository, it doesn't sync to the capsule automatically.
  • BZ - 2103099 - satellite-clone fails to restore online backup on RHEL8
  • BZ - 2103102 - MemoryError when importing large repo to disconnected Satellite
  • BZ - 2103106 - Attempt to disable a Red Hat Repository fails with error "Cannot delete record because of dependent library_instances_inverse" if the repository is part of any CV versions in Satellite 6.10
  • BZ - 2103110 - undefined method `find' for nil:NilClass when importing content that has gpg_keys associated to it
  • BZ - 2103129 - RHEL 9 appstream and baseos not showing as recommended repositories
  • BZ - 2103522 - Capsule sync fails with "Parsing interrupted: The repository metadata being synced into Pulp is erroneous in a way that makes it ambiguous (duplicate NEVRAs).."
  • BZ - 2104401 - Improve speed of manifest refresh by running RefreshIfNeeded steps concurrently
  • BZ - 2104498 - Unable to sync jfrog artifactory-pro-rpms repository
  • BZ - 2105048 - Error 'modulemd-yaml-error-quark' while synchronizing fedora modular repository on Satellite 6.10.
  • BZ - 2105107 - Data issue for users on RHEL7 syncing EL8+ EPEL or Fedora Modular repositories
  • BZ - 2105144 - Scheduling a remote execution job through API calls are using UTC instead of timezone
  • BZ - 2105299 - Email notification shows incorrect new errata after syncing an Epel repository
  • BZ - 2105941 - After 6.10 to 6.11 upgrade on FIPS setup, repository sync operations fail with an error "[digital envelope routines: EVP_DigestInit_ex] disabled for fips"
  • BZ - 2106000 - Manifest Refresh should ensure environment-content association
  • BZ - 2106090 - Running smart-proxy-openscap-send command returns "Gemfile lists the gem rsec (< 1) more than once" on Satellite 6.10.
  • BZ - 2106091 - Exclude filter may exclude errata and packages that are needed
  • BZ - 2106092 - Manifest refresh randomly fails with "No such file or directory" when having multile dynflow workers
  • BZ - 2106093 - Simplify self-upgrade mechanism
  • BZ - 2106333 - Add Satellite and Capsule 6.12 upgrade scenarios
  • BZ - 2106659 - Inconsistent packages versioning
  • BZ - 2106691 - Satellite 6.12 still defaults to the legacy host UI
  • BZ - 2106700 - Invocations fail with NoMethodError - undefined method `code' if capsule loses script feature without satellite noticing
  • BZ - 2106885 - Upgrade to Satellite 6.11 fails in db:seed state with error "ActiveRecord::RecordInvalid: Validation failed: Name has already been taken"
  • BZ - 2107252 - Last item in Webhooks table is overflowing
  • BZ - 2107572 - packaging request for pull provider dependencies
  • BZ - 2107577 - execution of roles with missing modules doesn't fail the execution
  • BZ - 2107701 - [Pulp 3] If a modulemd metadata artifact is missing from the filesystem but has an artifact_id associated with it in database, "Verify Content Checksum" cannot fix this problem
  • BZ - 2108169 - foreman-maintain self-upgrade enables RH repos when custom repo mentioned with --maintenance-repo-label for RHEL8
  • BZ - 2108611 - Broken link when accessing the Registration Doc from the Satellite register hosts screen
  • BZ - 2108637 - Remote execution fails for SSH Default when Remote Execution configured for Kerberos Authentication
  • BZ - 2108719 - Upgrading to Satellite 6.11 fails on db:migrate stage with error "null value in column "created_at" violates not-null constraint"
  • BZ - 2109254 - Remove orphans task going to the paused state with error "Cannot delete some instances of model 'Repository' because they are referenced through protected foreign keys" on Red Hat Satellite 6.11
  • BZ - 2109260 - When using immediate downloads and retain_package_versions=X, all packages are downloaded and many are immediately orphaned
  • BZ - 2109298 - ModuleStreamErratumPackages aren't indexed at first repository syncing
  • BZ - 2109421 - Sendmail package not present on RHEL8 and needs manual configuration
  • BZ - 2109594 - After upgrading to Satellite 6.11 , foreman log is flooded with huge tracebacks related to "unknown class DockerRegistry, ignoring" and "unknown class Container, ignoring"
  • BZ - 2109606 - Not able to enable repositories when FIPS is enabled.
  • BZ - 2109810 - Search for string in n-v-r.a format fails for custom packages but not for Red Hat packages
  • BZ - 2110003 - smart-proxy consumes 100% cpu after connecting to WebConsole with krb5 auth on RHEL8
  • BZ - 2110163 - Generate All Reports Job Fails After Upgrade to 6.11 with Missing Logger Method
  • BZ - 2110222 - Insights client traffic through a Satellite 6.11 Capsule fails
  • BZ - 2110731 - [ BUG ] Sync errata email notification is not workng in Satellite 6.11 whereas "Test Email" functions fine
  • BZ - 2110872 - Moving between tabs generates "undefined method `parent_task' for nil:NilClass"
  • BZ - 2111038 - new host ui details,ansible roles, bug when all ansible roles are assigned
  • BZ - 2111074 - After LEAPP upgrade katello_candlepin_port_t definition is missing
  • BZ - 2111222 - Need a static ouia-id for the close button on the Confirmation Modal
  • BZ - 2111373 - new host ui details, edit ansible roles, when assigned, wait and not confirmed, role is unassigned automatically
  • BZ - 2111469 - Single host contains too many NICs
  • BZ - 2111570 - AVC denials noticed for gunicorn process after upgrading the Satellite 6.11 OS from RHEL 7 to RHEL 8 using leapp
  • BZ - 2111571 - Multiples of every module stream show in the web UI
  • BZ - 2111578 - Rebooting Sat611 on RHEL8 removes all pulp logs
  • BZ - 2111921 - [New Host UI] Ansible tab only shows "view all assigned roles" when at least one host specific role has been added
  • BZ - 2112015 - After deploying custom certs on Satellite, signed by a new CA, capsule can't fetch on-demand content
  • BZ - 2112093 - GUI shows "Capsule Authorization" disabled even if it was enabled during the creation of the webhook in Satellite 6.10
  • BZ - 2112098 - Need to be able to provide custom cert for ISS for Red Hat CDN
  • BZ - 2112436 - After initial build of a UEFI VM using Red Hat Satellite, the system fails to boot up with error "Partition with known EFI file not found" when VM Hardware version is 17 or above
  • BZ - 2112979 - Don't ship foreman-proxy-selinux in capsule repos
  • BZ - 2113013 - documentation button on capsule page goes to a broken link
  • BZ - 2113905 - [RHSSO] [Installer][RHEL8]- RHSSO feature settings are not getting enabled and failed with HTTPD CONF issue .
  • BZ - 2113946 - Mirroring complete ansible galaxy fails with the following message: 'NoneType' object has no attribute 'get'
  • BZ - 2113996 - Search for non-integer job id will result in error page
  • BZ - 2115229 - pull-provider rex jobs occassionally hanging
  • BZ - 2115686 - [RFE] Provide a functionality in Satellite to import pre-existing Ansible playbooks into Job Templates
  • BZ - 2115767 - Unable to apply all Errata via Remote Execution on Web UI with "Select All"
  • BZ - 2115775 - hammer command not working for non-root user post upgrading satellite to version 6.11
  • BZ - 2115822 - New host details UI does not work at all
  • BZ - 2115832 - Running "satellite-maintain self-upgrade" on a Satellite\Capsule 6.11.1.1 fails with error "Error: 'satellite-maintenance-6.11.2-for-rhel-8-x86_64-rpms' does not match a valid repository ID"
  • BZ - 2116123 - Even though the CreateRssNotifications job gets completed, It fails to fetch RSS with error '(NameError): uninitialized constant Foreman::HttpProxy::NetHttpExt' in Satellite 6.12
  • BZ - 2116276 - Hammmer task progress command returns Error: undefined method `empty?' for nil:NilClass
  • BZ - 2116385 - [RFE] Add deprecation warning/banner on Compute Resources page about deprecation of RHEV support
  • BZ - 2116871 - Package "python3-pulp_manifest" is not available in Satellite Utils repository
  • BZ - 2117382 - Only first certificate from a content credential is considered by katello when updating CDN configuration to use Network Sync
  • BZ - 2117489 - not all dependencies are allowed by foreman-protector
  • BZ - 2117522 - satellite-upgrade to 6.12 fails in packages-update step to resolve python dependencies
  • BZ - 2118055 - When installing errata via katello-agent, content_action_finish_timeout is ignored and tasks don't wait for client status to finish
  • BZ - 2118252 - dnf can't load foreman-protector.py as a regular user
  • BZ - 2118356 - katello-pull-transport-migrate missing in RHEL9 Client repos
  • BZ - 2118431 - Incremental export on repository exports not working correctly after syncably exporting repository
  • BZ - 2118689 - Boding interface bondig slaves are always changed to lower case
  • BZ - 2118694 - Upgrade fails during db:migrate with PG::ForeignKeyViolation: ERROR: ERROR: update or delete on table "katello_module_profiles" violates foreign key constraint "katello_mod_profile_rpm_mod_profile_id_fk" on table "katello_module_profile_rpms"
  • BZ - 2118772 - Satellite upgrade to 6.12 fails during db:migrate with PG::UndefinedColumn: ERROR: column "created_at" of relation "taxable_taxonomies" does not exist
  • BZ - 2118790 - Convert2rhel playbook tries to install RHEL8 convert2rhel package
  • BZ - 2118950 - Unable to configure cloud connector on Satellite 6.12.0
  • BZ - 2118966 - [Pulp3] When working with docker type repos, syslogs is flooded with warnings "The model <class 'pulp_container.app.models.ContainerNamespace'> defines the 'ACCESS_POLICY_VIEWSET_NAME' class attribute" in Satellite 6.12
  • BZ - 2119112 - subpaths field is mandatory while creating ACS in the UI
  • BZ - 2119117 - ACS create fails when --smart-proxy-ids option not passed with "undefined method `uniq' for nil:NilClass"
  • BZ - 2119120 - ACS create fails when same name used with "PG::UniqueViolation: ERROR: duplicate key value violates unique constraint"
  • BZ - 2119124 - ACS create form displays capsule names without spaces on review details page in UI
  • BZ - 2119190 - ACS create wizard: select capsule step says "Name source"
  • BZ - 2119234 - Timezone/timestamp issue with Ansible configuration management reports run via Capsule servers
  • BZ - 2119688 - running ansible default roles in Satellite 6.11.1.1 shows an error page
  • BZ - 2120148 - Remove spinner from Packages & Module streams tabs during REX job polling
  • BZ - 2120224 - Host collections card shows empty card without any text when no host collections are present
  • BZ - 2120299 - 'This host has errata that are applicable, but not installable' message incorrectly appears
  • BZ - 2120327 - Discovery Organization setting is shown as Discovery Location setting
  • BZ - 2120414 - Show arch restrictions on Repository Sets tab (new host details)
  • BZ - 2120579 - remote execution interface missing in global registration dialog
  • BZ - 2120632 - After Upgrading LEAPPed Satellite to 6.12 pulp is not connected to redis
  • BZ - 2120715 - Satellite 6.11 GUI documentation URL takes to a non existing URL with 404
  • BZ - 2120992 - Running satellite-clone on SAT6.12 fails beacuse it's not supported
  • BZ - 2121238 - Importing a custom repository with different label but same name causes validation error
  • BZ - 2121249 - Syncable Exports have spaces in the exported paths
  • BZ - 2121583 - Sync of an Ansible collection repo to the Capsule fails
  • BZ - 2121689 - foreman-maintain still enables ansible-2.9-for-rhel-8-x86_64-rpms repository for running an update to 6.11.z when no packages are installed from that repository
  • BZ - 2121738 - host details jobs - change from list to table
  • BZ - 2121739 - host details audits, change from list to table
  • BZ - 2121954 - When searching for content, dropdown filters are literal search terms.
  • BZ - 2122090 - Syncable exports not properly validated
  • BZ - 2122214 - katello-certs-check propose not valid command for capsule
  • BZ - 2122764 - Indexing error if a collection to be synced from galaxy doesn't have tags associated.
  • BZ - 2122780 - Pub url is not accessible on the Satellite nor Capsule server
  • BZ - 2122945 - Satellite manifest upload/import error: Unexpected exception occurred while executing transactional block
  • BZ - 2123352 - Updating katello-ca package does not update certs in yggdrasild service for REX pull mode client
  • BZ - 2123405 - [RFE] - Add rhel-6-server-els-rpms repository under recommended repositories
  • BZ - 2124047 - Accessing an external capsule from UI, shows "Last sync failed: 404 Not Found" even if the last capsule content sync was successful in Satellite 6.12
  • BZ - 2124051 - Ansible-type REX jobs are still delegated by satellite 6.12 to be executed via an external Capsule 6.12 even if the ansible feature is not enabled on the same
  • BZ - 2124087 - The "Change Content Source" option does not provides steps to change the yggdrasil configuration in case putt-mqtt mode is use in Satellite 6.12
  • BZ - 2124271 - After installing katello-agent on a RHEL 9 host, Goferd service fails to start with error AttributeError: 'Scheduler' object has no attribute 'isAlive'
  • BZ - 2124568 - 'candlepin-validate-db' pre-upgrade check fails with "Could not open SSL root certificate file /root/.postgresql/root.crt" error for external DB setup with SSL
  • BZ - 2124663 - Host details statuses clear button is always disabled
  • BZ - 2124850 - failure to enable async-ssh rex mode with Couldn't enable 'script'
  • BZ - 2124851 - Post upgrade to 6.11.z, DHCP error with wrong number of arguments for validate_supported_address
  • BZ - 2124928 - Webhooks page in UI is broken
  • BZ - 2125022 - Content View Versions generated by Export are still listed in Composite CVs page
  • BZ - 2125244 - Sync of a docker type repository containing schema 1 manifest fails with error
  • BZ - 2125317 - Fix details tab cards Expand/collapse all behavior
  • BZ - 2125585 - Satellite can not be installed on RHEL 8.7
  • BZ - 2125669 - Navigating to content view page from the left panel after creating a cv does not work
  • BZ - 2127099 - Unsupported Installer report plugin exist in the downstream Satellite 6.12
  • BZ - 2127318 - ACS create wizard: review details step displays password in plaintext when manual auth is selected
  • BZ - 2127934 - rex pull-provider client not configured during host provisioning
  • BZ - 2127940 - save_to_file macro does not work if the thing being saved contains a heredoc terminated with EOF
  • BZ - 2128209 - ssh-async rex job fails with OpenSSL::SSL::SSLError
  • BZ - 2128422 - Repository Sets on new Hosts details produces error page
  • BZ - 2129002 - ACS create wizard: select capsule shows duplicate entries in dual-list selector widget
  • BZ - 2131729 - Repository sets does not work on new host details page
  • BZ - 2133468 - Upgrade fails to apply rpm.0044_noartifact_modules pulpcore migration
  • BZ - 2139368 - can't save discovery settings on an upgraded Satellite 6.12
  • BZ - 2139369 - can't save bootdisk settings on an upgraded Satellite 6.12
  • BZ - 2139371 - can't save RH Cloud settings on an upgraded Satellite 6.12