-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Low: Satellite 6.10.3 Async Bug Fix Update
Advisory ID:       RHSA-2022:0790-01
Product:           Red Hat Satellite 6
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:0790
Issue date:        2022-03-08
CVE Names:         CVE-2021-4142 
====================================================================
1. Summary:

Updated Satellite 6.10 packages that fix several bugs are now available for
Red Hat Satellite.

2. Relevant releases/architectures:

Red Hat Satellite 6.10 - noarch
Red Hat Satellite Capsule 6.10 - noarch

3. Description:

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security Fix(es):
2043714 - CVE-2021-4142 candlepin: Satellite: Allow unintended SCA
certificate to authenticate Candlepin [rhn_satellite_6-default]

This update fixes the following bugs:

2043702 - Unable to sync EPEL repositories on Satellite 6.10 when 'Mirror
on Sync' is enabled
2043710 - Syncing tens of repos to capsule can cause deadlock: while
updating tuple (...) in relation "core_content"
2048306 - Satellite 6.10 may fail to sync content to capsule still in
version 6.9
2049760 - No longer be able to import content into disconnected Satellite
for existing content views
2053723 - Large repo sync failed with "Katello::Errors::Pulp3Error:
Response payload is not completed"
2053726 - After upgrading to 6.10, Satellite fails to sync some
repositories with large files with timeout error
2055660 - organization context fails to change in web UI
2055662 - Incremental CV update fails with 400 HTTP error 
2027367 - Satellite doesn't forward the "If-Modified-Since" header for
/accessible_content endpoint to Candlepin
2027786 - Satellite schedules one recurring
InventorySync::Async::InventoryScheduledSync per org but each task syncs
all orgs, resulting in harmless but unnecessary tasks
2043697 - null value in column "manifest_id" violates not-null constraint
error while syncing RHOSP container images
2043698 - Remote Execution fails to honor remote_execution_connect_by_ip
override on host
2043699 - Content view export failed with undefined method `first' for
nil:NilClass
2043700 - webhook event "build_exited" never gets triggered
2043701 - Ansible roles are not starting automatically after provisioning
2043704 - Syncing sha-checksummed KS repository fails with: " Artifact()
got an unexpected keyword argument 'sha' "
2043705 - db:seed can fail when there are host mismatches
2043706 - New OS created due to facts mismatch for operatingsystem for
RHSM, Puppet and Ansible
2043707 - Satellite upgrade to 6.10.1 fails with multiple rubygem-sinatra
package dependency errors2043712 - pulpcore-workers grow very large when repositories have many
changelog entries
2043715 - Limited CV docker tags cannot be pulled after syncing library
repo with "limit sync tags"
2043716 - 406 error appears when running insights-client --compliance
2043719 - Incremental publish content view doesn't copy any contents
2043720 - ERROR: at least one Erratum record has migrated_pulp3_href NULL
value
2047345 - New version of Candlepin now has org in entitlement certificate
and causes authorization issues

Users of Red Hat Satellite are advised to upgrade to these updated
packages, which fix these bugs.

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.10/html/upgrading_and_updating_red_hat_satellite/updating_satellite_server_capsule_server_and_content_hosts

5. Bugs fixed (https://bugzilla.redhat.com/):

2027367 - Satellite doesn't forward the "If-Modified-Since" header for /accessible_content endpoint to Candlepin
2027786 - Satellite schedules one recurring InventorySync::Async::InventoryScheduledSync per org but each task syncs all orgs, resulting in harmless but unnecessary tasks
2034346 - CVE-2021-4142 Satellite: Allow unintended SCA certificate to authenticate Candlepin
2043697 - null value in column "manifest_id" violates not-null constraint error while syncing RHOSP container images
2043698 - Remote Execution fails to honor remote_execution_connect_by_ip override on host
2043699 - Content view export failed with undefined method `first' for nil:NilClass
2043700 - webhook event "build_exited" never gets triggered
2043701 - Ansible roles are not starting automatically after provisioning
2043702 - Unable to sync EPEL repositories on Satellite 6.10 when 'Mirror on Sync' is enabled
2043704 - Syncing sha-checksummed  KS repository fails with:  "  Artifact() got an unexpected keyword argument 'sha' "
2043705 - db:seed can fail when there are host mismatches
2043706 - New OS created due to facts mismatch for operatingsystem for RHSM, Puppet and Ansible
2043707 - Satellite upgrade to 6.10.1 fails with multiple rubygem-sinatra package dependency errors2043710 - syncing tens of repos to capsule can cause deadlock: while updating tuple (...) in relation "core_content"
2043712 - pulpcore-workers grow very large when repositories have many changelog entries
2043715 - Limited CV docker tags cannot be pulled after syncing library repo with "limit sync tags"
2043716 - 406 error appears when running insights-client --compliance
2043719 - Incremental publish content view doesn't copy any contents
2043720 - ERROR: at least one Erratum record has migrated_pulp3_href NULL value
2047345 - New version of Candlepin now has org in entitlement certificate and causes authorization issues
2048306 - Satellite 6.10 may fail to sync content to capsule still in version 6.9
2049760 - No longer be able to import content into disconnected Satellite for existing content views
2053723 - Large repo sync failed with "Katello::Errors::Pulp3Error: Response payload is not completed"
2053726 - After upgrading to 6.10, Satellite fails to sync some repositories with large files with timeout error
2055660 - organization context fails to change in web UI
2055662 - Incremental CV update fails with 400 HTTP error

6. Package List:

Red Hat Satellite Capsule 6.10:

Source:
foreman-2.5.2.19-1.el7sat.src.rpm
python-aiohttp-xmlrpc-1.3.2-0.1.el7pc.src.rpm
python-pulp-container-2.8.4-0.1.el7pc.src.rpm
python-pulp-rpm-3.14.12-1.el7pc.src.rpm
python-pulpcore-3.14.12-1.el7pc.src.rpm
satellite-6.10.3-1.el7sat.src.rpm

noarch:
foreman-debug-2.5.2.19-1.el7sat.noarch.rpm
python3-aiohttp-xmlrpc-1.3.2-0.1.el7pc.noarch.rpm
python3-pulp-container-2.8.4-0.1.el7pc.noarch.rpm
python3-pulp-rpm-3.14.12-1.el7pc.noarch.rpm
python3-pulpcore-3.14.12-1.el7pc.noarch.rpm
satellite-capsule-6.10.3-1.el7sat.noarch.rpm
satellite-common-6.10.3-1.el7sat.noarch.rpm

Red Hat Satellite 6.10:

Source:
candlepin-4.0.15-1.el7sat.src.rpm
foreman-2.5.2.19-1.el7sat.src.rpm
python-aiohttp-xmlrpc-1.3.2-0.1.el7pc.src.rpm
python-pulp-container-2.8.4-0.1.el7pc.src.rpm
python-pulp-rpm-3.14.12-1.el7pc.src.rpm
python-pulpcore-3.14.12-1.el7pc.src.rpm
satellite-6.10.3-1.el7sat.src.rpm
tfm-rubygem-foreman_ansible-6.3.4.1-1.el7sat.src.rpm
tfm-rubygem-foreman_rh_cloud-4.0.31-1.el7sat.src.rpm
tfm-rubygem-katello-4.1.1.48-1.el7sat.src.rpm
tfm-rubygem-pulp_rpm_client-3.14.12.1-1.el7sat.src.rpm

noarch:
candlepin-4.0.15-1.el7sat.noarch.rpm
candlepin-selinux-4.0.15-1.el7sat.noarch.rpm
foreman-2.5.2.19-1.el7sat.noarch.rpm
foreman-cli-2.5.2.19-1.el7sat.noarch.rpm
foreman-debug-2.5.2.19-1.el7sat.noarch.rpm
foreman-dynflow-sidekiq-2.5.2.19-1.el7sat.noarch.rpm
foreman-ec2-2.5.2.19-1.el7sat.noarch.rpm
foreman-gce-2.5.2.19-1.el7sat.noarch.rpm
foreman-journald-2.5.2.19-1.el7sat.noarch.rpm
foreman-libvirt-2.5.2.19-1.el7sat.noarch.rpm
foreman-openstack-2.5.2.19-1.el7sat.noarch.rpm
foreman-ovirt-2.5.2.19-1.el7sat.noarch.rpm
foreman-postgresql-2.5.2.19-1.el7sat.noarch.rpm
foreman-service-2.5.2.19-1.el7sat.noarch.rpm
foreman-telemetry-2.5.2.19-1.el7sat.noarch.rpm
foreman-vmware-2.5.2.19-1.el7sat.noarch.rpm
python3-aiohttp-xmlrpc-1.3.2-0.1.el7pc.noarch.rpm
python3-pulp-container-2.8.4-0.1.el7pc.noarch.rpm
python3-pulp-rpm-3.14.12-1.el7pc.noarch.rpm
python3-pulpcore-3.14.12-1.el7pc.noarch.rpm
satellite-6.10.3-1.el7sat.noarch.rpm
satellite-cli-6.10.3-1.el7sat.noarch.rpm
satellite-common-6.10.3-1.el7sat.noarch.rpm
tfm-rubygem-foreman_ansible-6.3.4.1-1.el7sat.noarch.rpm
tfm-rubygem-foreman_rh_cloud-4.0.31-1.el7sat.noarch.rpm
tfm-rubygem-katello-4.1.1.48-1.el7sat.noarch.rpm
tfm-rubygem-pulp_rpm_client-3.14.12.1-1.el7sat.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2021-4142
https://access.redhat.com/security/updates/classification/#low

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYigaStzjgjWX9erEAQiLAxAAm8vk/9Bd3VEDhGQwzduXVEY0W2yf6Fi9
97UwhCwpt/pF8etYpOXTs2WRdQRPTJUzYalieAXxdDbqL3szMGXhRRkw8bad/ucn
WXNJ6R/hCl0uiopp/3uIEEPCKGgDWhC6p8mz1MUS3TxDxTMRjpPMPuABQkxAyk8o
rCuzc6WfcucvQK0Dd0+kr6yCQKA16SLp1vrcIuAfimOjwx/GIm9vLAgHNTlXkJ6y
aJ31NCmtwB6V20Gdt7fKn6n/OD8jDgZOnJIy6USU021VlB2P7/Jb/FzxfntIRpBX
n7iZR55eZTFSb+zd4HAtevB1/VfjY9SnD0QVtAtrBGx/G9Jb1gkzbHHtnEjNWTaT
oy6FxX0N3XIiKstcvYJ7hip7VcWVzfWv4rh4yknBgbtaToa9nSiOylmND6ObF7ZM
iGia+rjw7C3kU7P7tpFKeO4fRQygRcanKv6e17kfj++PejRBzkaQa7oYK0p0AaOM
BhFROQYiCegl/E9idgR+GTVsvmtYsQBPOwzGnwPFHgYH4+E83Ef3MlJNZHKKo6D5
HSdncLovNu70zQX5X66B6qXQEpCjBtOOo1EbwVg2cz5laDDnXB9gURh9GugXhpfd
uUpMLRNB+QtHig4NSNxYs6vBSuqhrrGbtk4Ijdets6uGfGlbds/w/HlRA2X5tTmR
m9LK2btMS7k=MJ3J
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-0790:01 Low: Satellite 6.10.3 Async Bug Fix Update

Updated Satellite 6.10 packages that fix several bugs are now available for Red Hat Satellite

Summary

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments.
Security Fix(es): 2043714 - CVE-2021-4142 candlepin: Satellite: Allow unintended SCA certificate to authenticate Candlepin [rhn_satellite_6-default]
This update fixes the following bugs:
2043702 - Unable to sync EPEL repositories on Satellite 6.10 when 'Mirror on Sync' is enabled 2043710 - Syncing tens of repos to capsule can cause deadlock: while updating tuple (...) in relation "core_content" 2048306 - Satellite 6.10 may fail to sync content to capsule still in version 6.9 2049760 - No longer be able to import content into disconnected Satellite for existing content views 2053723 - Large repo sync failed with "Katello::Errors::Pulp3Error: Response payload is not completed" 2053726 - After upgrading to 6.10, Satellite fails to sync some repositories with large files with timeout error 2055660 - organization context fails to change in web UI 2055662 - Incremental CV update fails with 400 HTTP error 2027367 - Satellite doesn't forward the "If-Modified-Since" header for /accessible_content endpoint to Candlepin 2027786 - Satellite schedules one recurring InventorySync::Async::InventoryScheduledSync per org but each task syncs all orgs, resulting in harmless but unnecessary tasks 2043697 - null value in column "manifest_id" violates not-null constraint error while syncing RHOSP container images 2043698 - Remote Execution fails to honor remote_execution_connect_by_ip override on host 2043699 - Content view export failed with undefined method `first' for nil:NilClass 2043700 - webhook event "build_exited" never gets triggered 2043701 - Ansible roles are not starting automatically after provisioning 2043704 - Syncing sha-checksummed KS repository fails with: " Artifact() got an unexpected keyword argument 'sha' " 2043705 - db:seed can fail when there are host mismatches 2043706 - New OS created due to facts mismatch for operatingsystem for RHSM, Puppet and Ansible 2043707 - Satellite upgrade to 6.10.1 fails with multiple rubygem-sinatra package dependency errors2043712 - pulpcore-workers grow very large when repositories have many changelog entries 2043715 - Limited CV docker tags cannot be pulled after syncing library repo with "limit sync tags" 2043716 - 406 error appears when running insights-client --compliance 2043719 - Incremental publish content view doesn't copy any contents 2043720 - ERROR: at least one Erratum record has migrated_pulp3_href NULL value 2047345 - New version of Candlepin now has org in entitlement certificate and causes authorization issues
Users of Red Hat Satellite are advised to upgrade to these updated packages, which fix these bugs.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For detailed instructions how to apply this update, refer to:
https://access.redhat.com/documentation/en-us/red_hat_satellite/6.10/html/upgrading_and_updating_red_hat_satellite/updating_satellite_server_capsule_server_and_content_hosts

References

https://access.redhat.com/security/cve/CVE-2021-4142 https://access.redhat.com/security/updates/classification/#low

Package List

Red Hat Satellite Capsule 6.10:
Source: foreman-2.5.2.19-1.el7sat.src.rpm python-aiohttp-xmlrpc-1.3.2-0.1.el7pc.src.rpm python-pulp-container-2.8.4-0.1.el7pc.src.rpm python-pulp-rpm-3.14.12-1.el7pc.src.rpm python-pulpcore-3.14.12-1.el7pc.src.rpm satellite-6.10.3-1.el7sat.src.rpm
noarch: foreman-debug-2.5.2.19-1.el7sat.noarch.rpm python3-aiohttp-xmlrpc-1.3.2-0.1.el7pc.noarch.rpm python3-pulp-container-2.8.4-0.1.el7pc.noarch.rpm python3-pulp-rpm-3.14.12-1.el7pc.noarch.rpm python3-pulpcore-3.14.12-1.el7pc.noarch.rpm satellite-capsule-6.10.3-1.el7sat.noarch.rpm satellite-common-6.10.3-1.el7sat.noarch.rpm
Red Hat Satellite 6.10:
Source: candlepin-4.0.15-1.el7sat.src.rpm foreman-2.5.2.19-1.el7sat.src.rpm python-aiohttp-xmlrpc-1.3.2-0.1.el7pc.src.rpm python-pulp-container-2.8.4-0.1.el7pc.src.rpm python-pulp-rpm-3.14.12-1.el7pc.src.rpm python-pulpcore-3.14.12-1.el7pc.src.rpm satellite-6.10.3-1.el7sat.src.rpm tfm-rubygem-foreman_ansible-6.3.4.1-1.el7sat.src.rpm tfm-rubygem-foreman_rh_cloud-4.0.31-1.el7sat.src.rpm tfm-rubygem-katello-4.1.1.48-1.el7sat.src.rpm tfm-rubygem-pulp_rpm_client-3.14.12.1-1.el7sat.src.rpm
noarch: candlepin-4.0.15-1.el7sat.noarch.rpm candlepin-selinux-4.0.15-1.el7sat.noarch.rpm foreman-2.5.2.19-1.el7sat.noarch.rpm foreman-cli-2.5.2.19-1.el7sat.noarch.rpm foreman-debug-2.5.2.19-1.el7sat.noarch.rpm foreman-dynflow-sidekiq-2.5.2.19-1.el7sat.noarch.rpm foreman-ec2-2.5.2.19-1.el7sat.noarch.rpm foreman-gce-2.5.2.19-1.el7sat.noarch.rpm foreman-journald-2.5.2.19-1.el7sat.noarch.rpm foreman-libvirt-2.5.2.19-1.el7sat.noarch.rpm foreman-openstack-2.5.2.19-1.el7sat.noarch.rpm foreman-ovirt-2.5.2.19-1.el7sat.noarch.rpm foreman-postgresql-2.5.2.19-1.el7sat.noarch.rpm foreman-service-2.5.2.19-1.el7sat.noarch.rpm foreman-telemetry-2.5.2.19-1.el7sat.noarch.rpm foreman-vmware-2.5.2.19-1.el7sat.noarch.rpm python3-aiohttp-xmlrpc-1.3.2-0.1.el7pc.noarch.rpm python3-pulp-container-2.8.4-0.1.el7pc.noarch.rpm python3-pulp-rpm-3.14.12-1.el7pc.noarch.rpm python3-pulpcore-3.14.12-1.el7pc.noarch.rpm satellite-6.10.3-1.el7sat.noarch.rpm satellite-cli-6.10.3-1.el7sat.noarch.rpm satellite-common-6.10.3-1.el7sat.noarch.rpm tfm-rubygem-foreman_ansible-6.3.4.1-1.el7sat.noarch.rpm tfm-rubygem-foreman_rh_cloud-4.0.31-1.el7sat.noarch.rpm tfm-rubygem-katello-4.1.1.48-1.el7sat.noarch.rpm tfm-rubygem-pulp_rpm_client-3.14.12.1-1.el7sat.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2022:0790-01
Product: Red Hat Satellite 6
Advisory URL: https://access.redhat.com/errata/RHSA-2022:0790
Issued Date: : 2022-03-08
CVE Names: CVE-2021-4142

Topic

Updated Satellite 6.10 packages that fix several bugs are now available forRed Hat Satellite.


Topic


 

Relevant Releases Architectures

Red Hat Satellite 6.10 - noarch

Red Hat Satellite Capsule 6.10 - noarch


Bugs Fixed

2027367 - Satellite doesn't forward the "If-Modified-Since" header for /accessible_content endpoint to Candlepin

2027786 - Satellite schedules one recurring InventorySync::Async::InventoryScheduledSync per org but each task syncs all orgs, resulting in harmless but unnecessary tasks

2034346 - CVE-2021-4142 Satellite: Allow unintended SCA certificate to authenticate Candlepin

2043697 - null value in column "manifest_id" violates not-null constraint error while syncing RHOSP container images

2043698 - Remote Execution fails to honor remote_execution_connect_by_ip override on host

2043699 - Content view export failed with undefined method `first' for nil:NilClass

2043700 - webhook event "build_exited" never gets triggered

2043701 - Ansible roles are not starting automatically after provisioning

2043702 - Unable to sync EPEL repositories on Satellite 6.10 when 'Mirror on Sync' is enabled

2043704 - Syncing sha-checksummed KS repository fails with: " Artifact() got an unexpected keyword argument 'sha' "

2043705 - db:seed can fail when there are host mismatches

2043706 - New OS created due to facts mismatch for operatingsystem for RHSM, Puppet and Ansible

2043707 - Satellite upgrade to 6.10.1 fails with multiple rubygem-sinatra package dependency errors2043710 - syncing tens of repos to capsule can cause deadlock: while updating tuple (...) in relation "core_content"

2043712 - pulpcore-workers grow very large when repositories have many changelog entries

2043715 - Limited CV docker tags cannot be pulled after syncing library repo with "limit sync tags"

2043716 - 406 error appears when running insights-client --compliance

2043719 - Incremental publish content view doesn't copy any contents

2043720 - ERROR: at least one Erratum record has migrated_pulp3_href NULL value

2047345 - New version of Candlepin now has org in entitlement certificate and causes authorization issues

2048306 - Satellite 6.10 may fail to sync content to capsule still in version 6.9

2049760 - No longer be able to import content into disconnected Satellite for existing content views

2053723 - Large repo sync failed with "Katello::Errors::Pulp3Error: Response payload is not completed"

2053726 - After upgrading to 6.10, Satellite fails to sync some repositories with large files with timeout error

2055660 - organization context fails to change in web UI

2055662 - Incremental CV update fails with 400 HTTP error


Related News