Important: Satellite 6.13.3 Async Security Update

Related Vulnerabilities: CVE-2022-40899   CVE-2023-0118  

Synopsis

Important: Satellite 6.13.3 Async Security Update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated Satellite 6.13 packages that fixes important security bugs and several
regular bugs are now available for Red Hat Satellite.

Description

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security fix(es):

foreman: Arbitrary code execution through templates. (CVE-2023-0118)
python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server (CVE-2022-40899)

This update fixes the following bugs:

2159659 - CVE-2023-0118 foreman: Arbitrary code execution through templates [rhn_satellite_6.13]
2211954 - nalfassi@redhat.com Unable to enable callback plugin per-template
2218653 - Unable to enable any repository in network sync
2218659 - Can't rerun a failed content-import task if it was exported using chunks
2218660 - "Host-Registered Content Hosts" Report gives error while generating - undefined method `nvra' for nil:NilClass
2218661 - Yet another deadlock during Capsule sync, now when existing content changed
2218954 - satellite6-bugs@redhat.com [Regression] VMware Image-based and full host boot disk based Provisioning fails with error-: Could not find virtual machine network interface matching <IP>
2218955 - CVE-2022-40899 python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server [rhn_satellite_6-default]
2218979 - Custom repo sync failed " Cannot open /var/lib/pulp/tmp/89726@satellite.example.com/tmpzmdau7qg/tmpy_kkhu3a: Cannot detect compression type"
2224023 - "undefined method `event' for nil:NilClass" in production.log when trying to remediate insights issues from CRC.
2218656 - satellite-maintain packages check-update fails when there are no packages to be updated.
2218657 - Should not be able to assign LE on the client profile which is not synced on the capsule server

Users of Red Hat Satellite are advised to upgrade to these updated
packages, which fix these bugs.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Satellite 6.13 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64

Fixes

  • BZ - 2159291 - CVE-2023-0118 Foreman: Arbitrary code execution through templates
  • BZ - 2165866 - CVE-2022-40899 python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server
  • BZ - 2211954 - Unable to enable callback plugin per-template
  • BZ - 2218653 - Unable to enable any repository in network sync
  • BZ - 2218656 - satellite-maintain packages check-update fails when there are no packages to be updated.
  • BZ - 2218657 - Should not be able to assign LE on the client profile which is not synced on the capsule server
  • BZ - 2218659 - Can't rerun a failed content-import task if it was exported using chunks
  • BZ - 2218660 - "Host-Registered Content Hosts" Report gives error while generating - undefined method `nvra' for nil:NilClass
  • BZ - 2218661 - Yet another deadlock during Capsule sync, now when existing content changed
  • BZ - 2218954 - [Regression] VMware Image-based and full host boot disk based Provisioning fails with error-: Could not find virtual machine network interface matching <IP>
  • BZ - 2218979 - Custom repo sync failed " Cannot open /var/lib/pulp/tmp/89726@satellite.example.com/tmpzmdau7qg/tmpy_kkhu3a: Cannot detect compression type"
  • BZ - 2224023 - "undefined method `event' for nil:NilClass" in production.log when trying to remediate insights issues from CRC.