RedHat: RHSA-2020-2740:01 Important: candlepin and satellite security update

    Date 24 Jun 2020
    167
    Posted By LinuxSecurity Advisories
    An update for candlepin and satellite is now available for Red Hat Satellite 6.5 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256
    
    =====================================================================
                       Red Hat Security Advisory
    
    Synopsis:          Important: candlepin and satellite security update
    Advisory ID:       RHSA-2020:2740-01
    Product:           Red Hat Satellite 6
    Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2740
    Issue date:        2020-06-24
    CVE Names:         CVE-2019-10086 
    =====================================================================
    
    1. Summary:
    
    An update for candlepin and satellite is now available for Red Hat
    Satellite 6.5 for RHEL 7.
    
    Red Hat Product Security has rated this update as having a security impact
    of Important. A Common Vulnerability Scoring System (CVSS) base score,
    which gives a detailed severity rating, is available for each vulnerability
    from the CVE link(s) in the References section.
    
    2. Relevant releases/architectures:
    
    Red Hat Satellite 6.5 - noarch
    Red Hat Satellite Capsule 6.5 - noarch
    
    3. Description:
    
    Red Hat Satellite is a system management solution that allows organizations
    to configure and maintain their systems without the necessity to provide
    public Internet access to their servers or other client systems. It
    performs provisioning and configuration management of predefined standard
    operating environments.
    
    Security Fix(es):
    
    * apache-commons-beanutils: does not suppresses the class property in
    PropertyUtilsBean by default (CVE-2019-10086)
    
    For more details about the security issue(s), including the impact, a CVSS
    score, acknowledgments, and other related information, refer to the CVE
    page(s) listed in the References section.
    
    4. Solution:
    
    Before applying this update, make sure all previously released errata
    relevant to your system have been applied.
    
    For detailed instructions how to apply this update, refer to:
    
    https://access.redhat.com/documentation/en-us/red_hat_satellite/6.6/html/up
    grading_and_updating_red_hat_satellite/updating_satellite_server_capsule_se
    rver_and_content_hosts
    
    5. Bugs fixed (https://bugzilla.redhat.com/):
    
    1767483 - CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default
    
    6. Package List:
    
    Red Hat Satellite Capsule 6.5:
    
    Source:
    satellite-6.5.3.2-1.el7sat.src.rpm
    
    noarch:
    satellite-capsule-6.5.3.2-1.el7sat.noarch.rpm
    satellite-common-6.5.3.2-1.el7sat.noarch.rpm
    satellite-debug-tools-6.5.3.2-1.el7sat.noarch.rpm
    
    Red Hat Satellite 6.5:
    
    Source:
    candlepin-2.5.22-1.el7sat.src.rpm
    satellite-6.5.3.2-1.el7sat.src.rpm
    
    noarch:
    candlepin-2.5.22-1.el7sat.noarch.rpm
    candlepin-selinux-2.5.22-1.el7sat.noarch.rpm
    satellite-6.5.3.2-1.el7sat.noarch.rpm
    satellite-capsule-6.5.3.2-1.el7sat.noarch.rpm
    satellite-cli-6.5.3.2-1.el7sat.noarch.rpm
    satellite-common-6.5.3.2-1.el7sat.noarch.rpm
    satellite-debug-tools-6.5.3.2-1.el7sat.noarch.rpm
    
    These packages are GPG signed by Red Hat for security.  Our key and
    details on how to verify the signature are available from
    https://access.redhat.com/security/team/key/
    
    7. References:
    
    https://access.redhat.com/security/cve/CVE-2019-10086
    https://access.redhat.com/security/updates/classification/#important
    
    8. Contact:
    
    The Red Hat security contact is . More contact
    details at https://access.redhat.com/security/team/contact/
    
    Copyright 2020 Red Hat, Inc.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1
    
    iQIVAwUBXvNf9tzjgjWX9erEAQiM/Q//Zb39r+xCmnDeLn25bgTOSFo0RpYioVzm
    5bnuJoKgQyE8kvCXcvt/sTYzO3LJqrNd8I0m3gKWzX+RNWkeJ5W6NsYw9xGycpoP
    05beeqF1OCGekEkpEiIG2BBhyh6RHJ96/5QekO6SbncyZakB3LwoeP6ZBhgMQOXd
    KTaGZcMz1huhBSrnQF+lfXnSyLScSEvQfZigJ0fNJ9BgdCiZcYIe10QyCVgYvKiR
    KbiWFjVMyLJvlh/LC+Wt/GG3A8XD6jCnP7joEteEEvaNmG04ipKZ3+m+wOAIjRC0
    GqSbg365/doj9XoqCtFgGUWqP80+wa3JKo8m4ZjWGO3OPCLUqpFbKNLq1iQSrGyW
    s4T46eLzlOlOoCIMTJ3m4b+o7ozQAJa3wZfe/vFEe0uwYmrXn8I/CsZvYV8TckWf
    xF4CcBfbUHQ6WQWpXZ7aTG9Q/7zapwaIJ+HatGdQK381tCQ85JggjqpdGksx9XW4
    fWGpuRljRYZQ+HB+BLGaq4EkxLseCyNg6ek86BL3Cv9rxdFZLFV+A8/68iT6LhLE
    75cXWk7ruDKvbsJxtKGC5OorQxMUZbugkQSS8fyRt8NcAKbYTLFfPkZxm3MzQ1/d
    YicuT+1oDmH4sP8KYTx8DU7QHXGOcAKfOKQGlA6zTyLtTUUDpEMOVBYmaY65PSKg
    10EO7jr30lM=
    =pC9g
    -----END PGP SIGNATURE-----
    
    --
    RHSA-announce mailing list
    This email address is being protected from spambots. You need JavaScript enabled to view it.
    https://www.redhat.com/mailman/listinfo/rhsa-announce
    

    LinuxSecurity Poll

    Are you considering making the switch to Purism's new Librem 14 Linux laptop to improve your security and privacy online?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/31-are-you-considering-making-the-switch-to-purism-s-new-librem-14-linux-laptop-to-improve-your-security-and-privacy-online?task=poll.vote&format=json
    31
    radio
    [{"id":"109","title":"Yes - the hardware kill switches and default ad blocking\/tracking protection sold me on it.","votes":"3","type":"x","order":"1","pct":37.5,"resources":[]},{"id":"110","title":"Not sure yet - I need to do more research.","votes":"4","type":"x","order":"2","pct":50,"resources":[]},{"id":"111","title":"No - I'm satisfied with my current laptop and have no security\/privacy concerns.","votes":"1","type":"x","order":"3","pct":12.5,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
    bottom 200

    Advisories

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.