-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: RHUI 4.5.0 release - Security, Bug Fixes, and Enhancements Advisory ID: RHSA-2023:4591-01 Product: Red Hat Update Infrastructure Advisory URL: https://access.redhat.com/errata/RHSA-2023:4591 Issue date: 2023-08-09 CVE Names: CVE-2023-30608 CVE-2023-31047 ===================================================================== 1. Summary: An updated version of Red Hat Update Infrastructure (RHUI) is now available. RHUI 4.5 fixes several security and operational bugs and also adds several new features. 2. Relevant releases/architectures: RHUI 4 for RHEL 8 - noarch 3. Description: Red Hat Update Infrastructure (RHUI) offers a highly scalable, highly redundant framework that enables you to manage repositories and content. It also enables cloud providers to deliver content and updates to Red Hat Enterprise Linux (RHEL) instances. Security Fix(es): * Django: Potential bypass of validation when uploading multiple files using a single form field (CVE-2023-31047) * sqlparse: Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) (CVE-2023-30608) This RHUI update fixes the following bugs: * Previously, the `rhui-manager` command used the `logname` command to obtain the login name. However, when `rhui-manager` is run using the `rhui-repo-sync` cron job, a login name is not defined. Consequently, emails sent by the cron job contained the error message `logname: no login name`. With this update, `rhui-manager` does not obtain the login name using the `logname` command and the error message is no longer generated. * Previously, when an invalid repository ID was used with the `rhui-manager` command to synchronize or delete a repository, the command failed with following error: `An unexpected error has occurred during the last operation.` Additionally, a traceback was also logged. With this update, the error message has been improved and failure to run no longer logs a traceback. This RHUI update introduces the following enhancements: * With this update, the client configuration RPMs in `rhui-manager` prevent subscription manager from automatically enabling `yum` plugins. As a result, RHUI repository users will no longer see irrelevant messages from subscription manager. (BZ#1957871) * With this update, you can generate machine-readable files with the status of each RHUI repository. To use this feature, run the following command: `rhui-manager --non-interactive status --repo_json