Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Red Hat Satellite is a systems management tool for Linux-based
infrastructure. It allows for provisioning, remote management, and
monitoring of multiple Linux deployments with a single centralized tool.
Security Fix(es):
* python-ecdsa: Unexpected and undocumented exceptions during signature
decoding (CVE-2019-14853)
* python-ecdsa: DER encoding is not being verified in signatures
(CVE-2019-14859)
* rubygem-activerecord-session_store: hijack sessions by using timing
attacks targeting the session id (CVE-2019-25025)
* rake: OS Command Injection via egrep in Rake::FileList (CVE-2020-8130)
* candlepin: guava - local information disclosure via temporary directory
created with unsafe permissions (CVE-2020-8908)
* PyYAML: incomplete fix for CVE-2020-1747 (CVE-2020-14343)
* tfm-rubygem-nokogiri: XML external entity injection via
Nokogiri::XML::Schema (CVE-2020-26247)
* tfm-rubygem-foreman_azure_rm: Azure compute resource secret_key leak to
authenticated users (CVE-2021-3413)
* foreman: possible man-in-the-middle in smart_proxy realm_freeipa
(CVE-2021-3494)
* foreman: BMC controller credential leak via API (CVE-2021-20256)
* python-aiohttp: Open redirect in
aiohttp.web_middlewares.normalize_path_middleware (CVE-2021-21330)
* rubygem-actionpack: Possible Information Disclosure / Unintended Method
Execution in Action Pack (CVE-2021-22885)
* tfm-rubygem-actionpack: rails: Possible Denial of Service vulnerability
in Action Dispatch (CVE-2021-22902)
* tfm-rubygem-actionpack: Possible DoS Vulnerability in Action Controller
Token Authentication (CVE-2021-22904)
* python-django: potential directory-traversal via uploaded files
(CVE-2021-28658)
* tfm-rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of
Service (DoS) (CVE-2021-29509)
* python-django: Potential directory-traversal via uploaded files
(CVE-2021-31542)
* tfm-rubygem-addressable: ReDoS in templates (CVE-2021-32740)
* python-django: Potential directory traversal via ``admindocs``
(CVE-2021-33203)
* python-urllib3: ReDoS in the parsing of authority part of URL
(CVE-2021-33503)
* python-django: Possible indeterminate SSRF, RFI, and LFI attacks since
validators accepted leading zeros in IPv4 addresses (CVE-2021-33571)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
* Updated Content Management backend with Pulp 3 for increased performance,
scale and reliability. MongoDB is also removed from Satellite
* Adds support for Azure GovCloud
* Provides Satellite 6.10 Server support for Satellite 6.9 Capsules
* Improves support for Satellite Air Gapped and Disconnected environments
* Adds Ansible Collections content type to support disconnected
environments
* Foreman_webhooks introduced to replace foreman_hooks
* Introduces UI to manage Personal Access Tokens
* Adds ability to configure Pulp repository synchronization timeouts
* Support for Convert2RHEL
* Provides advanced options when registering a host
* Supports remediation playbook signatures from console.redhat.com
* Red Hat Insights Plugin replaced through new integration within Satellite
* Ability to visually represent systems registered and in sync with
Insights
* Ability to verify if required packages are installed as part of
pre-upgrade check
* Ability to unset environment variables when installer is running
* Ability to turn backups on and off when cleaning up tasks from database
The items above are not a complete list of changes. This update also fixes
several bugs and adds various enhancements. Documentation for these changes
is available from the Release Notes document linked to in the References
section.
https://access.redhat.com/security/cve/CVE-2019-14853 https://access.redhat.com/security/cve/CVE-2019-14859 https://access.redhat.com/security/cve/CVE-2019-25025 https://access.redhat.com/security/cve/CVE-2020-8130 https://access.redhat.com/security/cve/CVE-2020-8908 https://access.redhat.com/security/cve/CVE-2020-14343 https://access.redhat.com/security/cve/CVE-2020-26247 https://access.redhat.com/security/cve/CVE-2021-3413 https://access.redhat.com/security/cve/CVE-2021-3494 https://access.redhat.com/security/cve/CVE-2021-20256 https://access.redhat.com/security/cve/CVE-2021-21330 https://access.redhat.com/security/cve/CVE-2021-22885 https://access.redhat.com/security/cve/CVE-2021-22902 https://access.redhat.com/security/cve/CVE-2021-22904 https://access.redhat.com/security/cve/CVE-2021-28658 https://access.redhat.com/security/cve/CVE-2021-29509 https://access.redhat.com/security/cve/CVE-2021-31542 https://access.redhat.com/security/cve/CVE-2021-32740 https://access.redhat.com/security/cve/CVE-2021-33203 https://access.redhat.com/security/cve/CVE-2021-33503 https://access.redhat.com/security/cve/CVE-2021-33571 https://access.redhat.com/security/updates/classification/#moderate
Red Hat Satellite Capsule 6.10:
Source:
ansible-collection-redhat-satellite-2.2.0-1.el7sat.src.rpm
ansible-collection-redhat-satellite_operations-0.3.2-1.el7sat.src.rpm
ansible-runner-1.4.6-1.el7ar.src.rpm
ansiblerole-foreman_scap_client-0.2.0-1.el7sat.src.rpm
ansiblerole-insights-client-1.7.1-1.el7sat.src.rpm
ansiblerole-satellite-receptor-installer-0.6.15-1.el7sat.src.rpm
createrepo_c-0.17.6-0.1.el7pc.src.rpm
foreman-2.5.2.17-2.el7sat.src.rpm
foreman-bootloaders-redhat-202005201200-1.el7sat.src.rpm
foreman-discovery-image-3.8.0-1.el7sat.src.rpm
foreman-discovery-image-service-1.0.0-4.1.el7sat.src.rpm
foreman-installer-2.5.2.10-1.el7sat.src.rpm
foreman-proxy-2.5.2-1.el7sat.src.rpm
foreman-selinux-2.5.2-1.el7sat.src.rpm
hfsplus-tools-332.14-12.el7.src.rpm
katello-4.1.1-2.el7sat.src.rpm
katello-certs-tools-2.7.3-1.el7sat.src.rpm
katello-client-bootstrap-1.7.7-1.el7sat.src.rpm
libcomps-0.1.15-1.el7pc.src.rpm
libmodulemd2-2.9.3-1.el7pc.src.rpm
libsodium-1.0.17-3.el7sat.src.rpm
libsolv-0.7.20-1.el7pc.src.rpm
pulpcore-selinux-1.2.6-1.el7pc.src.rpm
puppet-agent-6.22.1-1.el7sat.src.rpm
puppet-foreman_scap_client-0.4.0-1.el7sat.src.rpm
puppetlabs-stdlib-5.2.0-1.el7sat.src.rpm
puppetserver-6.15.3-1.el7sat.src.rpm
python-aiodns-3.0.0-1.el7pc.src.rpm
Read the Full Advisory
An update is now available for Red Hat Satellite 6.10 for RHEL 7.
Red Hat Satellite 6.10 - noarch, x86_64
Red Hat Satellite Capsule 6.10 - noarch, x86_64
1299602 - [RFE] Add email notification preferences for user for hammer command in satellite 6
1334989 - [RFE] Pulp download timeouts should be configurable
1392063 - Hammer --resolve-dependencies flag not working
1417752 - Satellite Capsule syncs error out when there are more than a certain amount of characters in the content view name
1437586 - Activation Key / Content View information always asking for content view
1548966 - [RFE] provide means to force recheck/redownload of pulp docker repos
1566630 - API in satellite 6.3 to view location parameter does not resolve the location name with location ID as it used to in satellite 6.2
1573241 - Repository selection not working on Activation Key's 'Repository Sets' tab
1583209 - [RFE] [Sat6] Text-Only errata are not included in hammer export causing errata count mismatch between connected and disconnected Satellite
1605147 - [RFE] Add SSH key passphrase support to ansible feature
1611621 - [RFE] Update Insights Plugin to use the new 'disconnected' option in Satellite 6.4
1615015 - [RFE] Do not backup tasks by default when cleaning up tasks from the database
1632961 - Creating an incremental export using hammer export --since command creating an full export.
1636403 - user with view_ansible_roles, import_ansible_roles foles can not import roles: AnsibleRole not found Please try to update your request
Get the latest Linux and open source security news straight to your inbox.