Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

RedHat: RHSA-2021-4702 Moderate: Satellite 6.10 Software Update

red hat
Calendar Grey November 16, 2021
Dist Redhat Esm H88
An important announcement for Red Hat Satellite 6.10 has been made, focusing on security enhancements and optimizing system administration.
An update is now available for Red Hat Satellite 6.10 for RHEL 7

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat Satellite is a systems management tool for Linux-based infrastructure. It allows for provisioning, remote management, and monitoring of multiple Linux deployments with a single centralized tool.
Security Fix(es): * python-ecdsa: Unexpected and undocumented exceptions during signature decoding (CVE-2019-14853) * python-ecdsa: DER encoding is not being verified in signatures (CVE-2019-14859) * rubygem-activerecord-session_store: hijack sessions by using timing attacks targeting the session id (CVE-2019-25025) * rake: OS Command Injection via egrep in Rake::FileList (CVE-2020-8130) * candlepin: guava - local information disclosure via temporary directory created with unsafe permissions (CVE-2020-8908) * PyYAML: incomplete fix for CVE-2020-1747 (CVE-2020-14343) * tfm-rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema (CVE-2020-26247) * tfm-rubygem-foreman_azure_rm: Azure compute resource secret_key leak to authenticated users (CVE-2021-3413) * foreman: possible man-in-the-middle in smart_proxy realm_freeipa (CVE-2021-3494) * foreman: BMC controller credential leak via API (CVE-2021-20256) * python-aiohttp: Open redirect in aiohttp.web_middlewares.normalize_path_middleware (CVE-2021-21330) * rubygem-actionpack: Possible Information Disclosure / Unintended Method Execution in Action Pack (CVE-2021-22885) * tfm-rubygem-actionpack: rails: Possible Denial of Service vulnerability in Action Dispatch (CVE-2021-22902) * tfm-rubygem-actionpack: Possible DoS Vulnerability in Action Controller Token Authentication (CVE-2021-22904) * python-django: potential directory-traversal via uploaded files (CVE-2021-28658) * tfm-rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS) (CVE-2021-29509) * python-django: Potential directory-traversal via uploaded files (CVE-2021-31542) * tfm-rubygem-addressable: ReDoS in templates (CVE-2021-32740) * python-django: Potential directory traversal via ``admindocs`` (CVE-2021-33203) * python-urllib3: ReDoS in the parsing of authority part of URL (CVE-2021-33503) * python-django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses (CVE-2021-33571)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
* Updated Content Management backend with Pulp 3 for increased performance, scale and reliability. MongoDB is also removed from Satellite * Adds support for Azure GovCloud * Provides Satellite 6.10 Server support for Satellite 6.9 Capsules * Improves support for Satellite Air Gapped and Disconnected environments * Adds Ansible Collections content type to support disconnected environments * Foreman_webhooks introduced to replace foreman_hooks * Introduces UI to manage Personal Access Tokens * Adds ability to configure Pulp repository synchronization timeouts * Support for Convert2RHEL * Provides advanced options when registering a host * Supports remediation playbook signatures from console.redhat.com * Red Hat Insights Plugin replaced through new integration within Satellite * Ability to visually represent systems registered and in sync with Insights * Ability to verify if required packages are installed as part of pre-upgrade check * Ability to unset environment variables when installer is running * Ability to turn backups on and off when cleaning up tasks from database
The items above are not a complete list of changes. This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

References

https://access.redhat.com/security/cve/CVE-2019-14853 https://access.redhat.com/security/cve/CVE-2019-14859 https://access.redhat.com/security/cve/CVE-2019-25025 https://access.redhat.com/security/cve/CVE-2020-8130 https://access.redhat.com/security/cve/CVE-2020-8908 https://access.redhat.com/security/cve/CVE-2020-14343 https://access.redhat.com/security/cve/CVE-2020-26247 https://access.redhat.com/security/cve/CVE-2021-3413 https://access.redhat.com/security/cve/CVE-2021-3494 https://access.redhat.com/security/cve/CVE-2021-20256 https://access.redhat.com/security/cve/CVE-2021-21330 https://access.redhat.com/security/cve/CVE-2021-22885 https://access.redhat.com/security/cve/CVE-2021-22902 https://access.redhat.com/security/cve/CVE-2021-22904 https://access.redhat.com/security/cve/CVE-2021-28658 https://access.redhat.com/security/cve/CVE-2021-29509 https://access.redhat.com/security/cve/CVE-2021-31542 https://access.redhat.com/security/cve/CVE-2021-32740 https://access.redhat.com/security/cve/CVE-2021-33203 https://access.redhat.com/security/cve/CVE-2021-33503 https://access.redhat.com/security/cve/CVE-2021-33571 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Satellite Capsule 6.10:
Source: ansible-collection-redhat-satellite-2.2.0-1.el7sat.src.rpm ansible-collection-redhat-satellite_operations-0.3.2-1.el7sat.src.rpm ansible-runner-1.4.6-1.el7ar.src.rpm ansiblerole-foreman_scap_client-0.2.0-1.el7sat.src.rpm ansiblerole-insights-client-1.7.1-1.el7sat.src.rpm ansiblerole-satellite-receptor-installer-0.6.15-1.el7sat.src.rpm createrepo_c-0.17.6-0.1.el7pc.src.rpm foreman-2.5.2.17-2.el7sat.src.rpm foreman-bootloaders-redhat-202005201200-1.el7sat.src.rpm foreman-discovery-image-3.8.0-1.el7sat.src.rpm foreman-discovery-image-service-1.0.0-4.1.el7sat.src.rpm foreman-installer-2.5.2.10-1.el7sat.src.rpm foreman-proxy-2.5.2-1.el7sat.src.rpm foreman-selinux-2.5.2-1.el7sat.src.rpm hfsplus-tools-332.14-12.el7.src.rpm katello-4.1.1-2.el7sat.src.rpm katello-certs-tools-2.7.3-1.el7sat.src.rpm katello-client-bootstrap-1.7.7-1.el7sat.src.rpm libcomps-0.1.15-1.el7pc.src.rpm libmodulemd2-2.9.3-1.el7pc.src.rpm libsodium-1.0.17-3.el7sat.src.rpm libsolv-0.7.20-1.el7pc.src.rpm pulpcore-selinux-1.2.6-1.el7pc.src.rpm puppet-agent-6.22.1-1.el7sat.src.rpm puppet-foreman_scap_client-0.4.0-1.el7sat.src.rpm puppetlabs-stdlib-5.2.0-1.el7sat.src.rpm puppetserver-6.15.3-1.el7sat.src.rpm python-aiodns-3.0.0-1.el7pc.src.rpm

Read the Full Advisory


Advisory ID: RHSA-2021:4702-01
Product: Red Hat Satellite 6
Issue date: 2021-11-16

Topic

An update is now available for Red Hat Satellite 6.10 for RHEL 7.

Relevant Releases Architectures

Red Hat Satellite 6.10 - noarch, x86_64

Red Hat Satellite Capsule 6.10 - noarch, x86_64

Bugs Fixed

1299602 - [RFE] Add email notification preferences for user for hammer command in satellite 6

1334989 - [RFE] Pulp download timeouts should be configurable

1392063 - Hammer --resolve-dependencies flag not working

1417752 - Satellite Capsule syncs error out when there are more than a certain amount of characters in the content view name

1437586 - Activation Key / Content View information always asking for content view

1548966 - [RFE] provide means to force recheck/redownload of pulp docker repos

1566630 - API in satellite 6.3 to view location parameter does not resolve the location name with location ID as it used to in satellite 6.2

1573241 - Repository selection not working on Activation Key's 'Repository Sets' tab

1583209 - [RFE] [Sat6] Text-Only errata are not included in hammer export causing errata count mismatch between connected and disconnected Satellite

1605147 - [RFE] Add SSH key passphrase support to ansible feature

1611621 - [RFE] Update Insights Plugin to use the new 'disconnected' option in Satellite 6.4

1615015 - [RFE] Do not backup tasks by default when cleaning up tasks from the database

1632961 - Creating an incremental export using hammer export --since command creating an full export.

1636403 - user with view_ansible_roles, import_ansible_roles foles can not import roles: AnsibleRole not found Please try to update your request

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here