Moderate: Satellite 6.14.1 Async Security Update

Related Vulnerabilities: CVE-2023-4886   CVE-2023-28362   CVE-2023-41040   CVE-2023-45803  

概述

Moderate: Satellite 6.14.1 Async Security Update

类型/严重性

Security Advisory: Moderate

Red Hat Insights 补丁分析

识别并修复受此公告影响的系统。

查看受影响的系统

标题

Updated Satellite 6.14 packages that fixes Important security bugs and several
regular bugs are now available for Red Hat Satellite.

描述

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security fix(es):

  • rubygem-actionpack: actionpack: Possible XSS via User Supplied Values to redirect_to [rhn_satellite_6.14] (CVE-2023-28362)
  • foreman: World readable file containing secrets [rhn_satellite_6.14] (CVE-2023-4886)
  • python-urllib3: urllib3: Request body not stripped after redirect from 303 status changes request method to GET [rhn_satellite_6-default] (CVE-2023-45803 )
  • python-gitpython: GitPython: Blind local file inclusion [rhn_satellite_6-default] (CVE-2023-41040)

This update fixes the following bugs:

2250342 - REX job finished with exit code 0 but the script failed on client side due to no space.
2250343 - Selinux denials are reported after following "Chapter 13. Managing Custom File Type Content" chapter step by step
2250344 - Long running postgres threads during content-export
2250345 - Upgrade django-import-export package to at least 3.1.0
2250349 - After upstream repo switched to zst compression, Satellite 6.12.5.1 unable to sync
2250350 - Slow generate applicability for Hosts with multiple modulestreams installed
2250352 - Recalculate button for Errata is not available on Satellite 6.13/ Satellite 6.14 if no errata is present
2250351 - Actions::ForemanLeapp::PreupgradeJob fails with null value in column "preupgrade_report_id" violates not-null constraint when run with non-admin user
2251799 - REX Template for 'convert2rhel analyze' command
2254085 - Getting '/usr/sbin/foreman-rake db:migrate' returned 1 instead of one of [0] ERROR while trying to upgrade Satellite 6.13 to 6.14
2254080 - satellite-convert2rhel-toolkit rpm v1.0.0 in 6.14.z

Users of Red Hat Satellite are advised to upgrade to these updated
packages, which fix these bugs.

解决方案

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Satellite 6.14 x86_64
  • Red Hat Satellite Capsule 6.14 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64

修复

  • BZ - 2217785 - CVE-2023-28362 actionpack: Possible XSS via User Supplied Values to redirect_to
  • BZ - 2230135 - CVE-2023-4886 foreman: World readable file containing secrets
  • BZ - 2246840 - CVE-2023-45803 urllib3: Request body not stripped after redirect from 303 status changes request method to GET
  • BZ - 2247040 - CVE-2023-41040 GitPython: Blind local file inclusion
  • BZ - 2250342 - REX job finished with exit code 0 but the script failed on client side due to no space.
  • BZ - 2250343 - Selinux denials are reported after following "Chapter 13. Managing Custom File Type Content" chapter step by step
  • BZ - 2250344 - Long running postgres threads during content-export
  • BZ - 2250345 - Upgrade django-import-export package to at least 3.1.0
  • BZ - 2250349 - After upstream repo switched to zst compression, Satellite 6.12.5.1 unable to sync
  • BZ - 2250350 - Slow generate applicability for Hosts with multiple modulestreams installed
  • BZ - 2250351 - Actions::ForemanLeapp::PreupgradeJob fails with null value in column "preupgrade_report_id" violates not-null constraint when run with non-admin user
  • BZ - 2250352 - Recalculate button for Errata is not available on Satellite 6.13/ Satellite 6.14 if no errata is present
  • BZ - 2251799 - REX Template for 'convert2rhel analyze' command
  • BZ - 2254080 - satellite-convert2rhel-toolkit rpm v1.0.0 in 6.14.z
  • BZ - 2254085 - Getting '/usr/sbin/foreman-rake db:migrate' returned 1 instead of one of [0] ERROR while trying to upgrade Satellite 6.13 to 6.14