Explore top 10 tips to secure your open-source projects now. Read More
×
Multiple vulnerabilities have been found in Keystone, the OpenStack identity service, including privilege escalation and authorization and access control flaws. CVE-2026-33551 An authenticated user with only a reader role may obtain an EC2/S3. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4611-1
Several security issues were fixed in ZooKeeper.. ========================================================================== Ubuntu Security Notice USN-6559-1 January 16, 2024 zookeeper vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in ZooKeeper. Software Description: - zookeeper: High-performance coordination service for distributed applications Details: It was discovered that ZooKeeper incorrectly handled authorization for the getACL() command. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2019-0201) Damien Diederen discovered that ZooKeeper incorrectly handled authorization if SASL Quorum Peer authentication is enabled. An attacker could possibly use this issue to bypass ZooKeeper's authorization system. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 23.04 and Ubuntu 23.10. (CVE-2023-44981) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: libzookeeper-java 3.8.0-11ubuntu0.1 Ubuntu 23.04: libzookeeper-java 3.8.0-10ubuntu0.1 Ubuntu 22.04 LTS: libzookeeper-java 3.4.13-6ubuntu4.1 Ubuntu 20.04 LTS: libzookeeper-java 3.4.13-5ubuntu0.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libzookeeper-java 3.4.13-3ubuntu0.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libzookeeper-java 3.4.8-1ubuntu0.1~esm2 Ubuntu 14.04 LTS (Available with Ubuntu Pro): libzookeeper-java 3.4.5+dfsg-1ubuntu0.1~esm3 In general, astandard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6559-1 CVE-2019-0201, CVE-2023-44981 Package Information: https://launchpad.net/ubuntu/+source/zookeeper/3.8.0-11ubuntu0.1 https://launchpad.net/ubuntu/+source/zookeeper/3.8.0-10ubuntu0.1 https://launchpad.net/ubuntu/+source/zookeeper/3.4.13-6ubuntu4.1 https://launchpad.net/ubuntu/+source/zookeeper/3.4.13-5ubuntu0.1 . Ubuntu Security Advisory USN-6559-1 pertains to several vulnerabilities identified in ZooKeeper, providing patches for multiple LTS versions.. ZooKeeper Security, Ubuntu Vulnerability, Authorization Issue, Remote Access Attack. . LinuxSecurity.com Team
An update for subscription-manager is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: subscription-manager security update Advisory ID: RHSA-2023:4701-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4701 Issue date: 2023-08-22 CVE Names: CVE-2023-3899 ===================================================================== 1. Summary: An update for subscription-manager is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 3. Description: The subscription-manager packages provide programs and libraries to allow users to manage subscriptions and yum repositories from the Red Hat entitlement platform. Security Fix(es): * subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration (CVE-2023-3899) For more details aboutthe security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2225407 - CVE-2023-3899 subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: subscription-manager-1.24.52-2.el7_9.src.rpm x86_64: python-syspurpose-1.24.52-2.el7_9.x86_64.rpm rhsm-gtk-1.24.52-2.el7_9.x86_64.rpm subscription-manager-1.24.52-2.el7_9.x86_64.rpm subscription-manager-debuginfo-1.24.52-2.el7_9.x86_64.rpm subscription-manager-gui-1.24.52-2.el7_9.x86_64.rpm subscription-manager-initial-setup-addon-1.24.52-2.el7_9.x86_64.rpm subscription-manager-migration-1.24.52-2.el7_9.x86_64.rpm subscription-manager-plugin-container-1.24.52-2.el7_9.x86_64.rpm subscription-manager-rhsm-1.24.52-2.el7_9.x86_64.rpm subscription-manager-rhsm-certificates-1.24.52-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): noarch: subscription-manager-cockpit-1.24.52-2.el7_9.noarch.rpm x86_64: subscription-manager-debuginfo-1.24.52-2.el7_9.x86_64.rpm subscription-manager-plugin-ostree-1.24.52-2.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: subscription-manager-1.24.52-2.el7_9.src.rpm x86_64: python-syspurpose-1.24.52-2.el7_9.x86_64.rpm subscription-manager-1.24.52-2.el7_9.x86_64.rpm subscription-manager-debuginfo-1.24.52-2.el7_9.x86_64.rpm subscription-manager-migration-1.24.52-2.el7_9.x86_64.rpm subscription-manager-plugin-container-1.24.52-2.el7_9.x86_64.rpm subscription-manager-rhsm-1.24.52-2.el7_9.x86_64.rpm subscription-manager-rhsm-certificates-1.24.52-2.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): noarch: subscription-manager-cockpit-1.24.52-2.el7_9.noarch.rpm x86_64: rhsm-gtk-1.24.52-2.el7_9.x86_64.rpm subscription-manager-debuginfo-1.24.52-2.el7_9.x86_64.rpm subscription-manager-gui-1.24.52-2.el7_9.x86_64.rpm subscription-manager-initial-setup-addon-1.24.52-2.el7_9.x86_64.rpm subscription-manager-plugin-ostree-1.24.52-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: subscription-manager-1.24.52-2.el7_9.src.rpm ppc64: python-syspurpose-1.24.52-2.el7_9.ppc64.rpm rhsm-gtk-1.24.52-2.el7_9.ppc64.rpm subscription-manager-1.24.52-2.el7_9.ppc64.rpm subscription-manager-debuginfo-1.24.52-2.el7_9.ppc64.rpm subscription-manager-gui-1.24.52-2.el7_9.ppc64.rpm subscription-manager-initial-setup-addon-1.24.52-2.el7_9.ppc64.rpm subscription-manager-migration-1.24.52-2.el7_9.ppc64.rpm subscription-manager-plugin-container-1.24.52-2.el7_9.ppc64.rpm subscription-manager-rhsm-1.24.52-2.el7_9.ppc64.rpm subscription-manager-rhsm-certificates-1.24.52-2.el7_9.ppc64.rpm ppc64le: python-syspurpose-1.24.52-2.el7_9.ppc64le.rpm rhsm-gtk-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-debuginfo-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-gui-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-initial-setup-addon-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-migration-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-plugin-container-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-rhsm-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-rhsm-certificates-1.24.52-2.el7_9.ppc64le.rpm s390x: python-syspurpose-1.24.52-2.el7_9.s390x.rpm rhsm-gtk-1.24.52-2.el7_9.s390x.rpm subscription-manager-1.24.52-2.el7_9.s390x.rpm subscription-manager-debuginfo-1.24.52-2.el7_9.s390x.rpm subscription-manager-gui-1.24.52-2.el7_9.s390x.rpm subscription-manager-initial-setup-addon-1.24.52-2.el7_9.s390x.rpm subscription-manager-migration-1.24.52-2.el7_9.s390x.rpm subscription-manager-plugin-container-1.24.52-2.el7_9.s390x.rpm subscription-manager-rhsm-1.24.52-2.el7_9.s390x.rpm subscription-manager-rhsm-certificates-1.24.52-2.el7_9.s390x.rpm x86_64: python-syspurpose-1.24.52-2.el7_9.x86_64.rpm rhsm-gtk-1.24.52-2.el7_9.x86_64.rpm subscription-manager-1.24.52-2.el7_9.x86_64.rpm subscription-manager-debuginfo-1.24.52-2.el7_9.x86_64.rpm subscription-manager-gui-1.24.52-2.el7_9.x86_64.rpm subscription-manager-initial-setup-addon-1.24.52-2.el7_9.x86_64.rpm subscription-manager-migration-1.24.52-2.el7_9.x86_64.rpm subscription-manager-plugin-container-1.24.52-2.el7_9.x86_64.rpm subscription-manager-rhsm-1.24.52-2.el7_9.x86_64.rpm subscription-manager-rhsm-certificates-1.24.52-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): noarch: subscription-manager-cockpit-1.24.52-2.el7_9.noarch.rpm ppc64: subscription-manager-debuginfo-1.24.52-2.el7_9.ppc64.rpm subscription-manager-plugin-ostree-1.24.52-2.el7_9.ppc64.rpm ppc64le: subscription-manager-debuginfo-1.24.52-2.el7_9.ppc64le.rpm subscription-manager-plugin-ostree-1.24.52-2.el7_9.ppc64le.rpm s390x: subscription-manager-debuginfo-1.24.52-2.el7_9.s390x.rpm subscription-manager-plugin-ostree-1.24.52-2.el7_9.s390x.rpm x86_64: subscription-manager-debuginfo-1.24.52-2.el7_9.x86_64.rpm subscription-manager-plugin-ostree-1.24.52-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: subscription-manager-1.24.52-2.el7_9.src.rpm x86_64: python-syspurpose-1.24.52-2.el7_9.x86_64.rpm rhsm-gtk-1.24.52-2.el7_9.x86_64.rpm subscription-manager-1.24.52-2.el7_9.x86_64.rpm subscription-manager-debuginfo-1.24.52-2.el7_9.x86_64.rpm subscription-manager-gui-1.24.52-2.el7_9.x86_64.rpm subscription-manager-initial-setup-addon-1.24.52-2.el7_9.x86_64.rpm subscription-manager-migration-1.24.52-2.el7_9.x86_64.rpm subscription-manager-plugin-container-1.24.52-2.el7_9.x86_64.rpm subscription-manager-rhsm-1.24.52-2.el7_9.x86_64.rpm subscription-manager-rhsm-certificates-1.24.52-2.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): noarch: subscription-manager-cockpit-1.24.52-2.el7_9.noarch.rpm x86_64: subscription-manager-debuginfo-1.24.52-2.el7_9.x86_64.rpm subscription-manager-plugin-ostree-1.24.52-2.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2023-3899 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJk5RhwAAoJENzjgjWX9erEPAoP/RrfFSWaeFVxlSKdbxhvddY8 GeTz+sFCeC6Jovu/qEZAW+dojO96hPsguseXGx9TLsCZgAEgpq4+fQXylqQuoMpv Y/6AZ67xwzSQ46MflFQkEjMi9UI/SiY69egoPkvg6GX7GymlbU7UGg6cM+2iIWBP XG/SCiUIiEcZnB+FrW9su2V0RinL2HmLXixhk5FMBEeP5mgR3xXDqmL70FpTgViF u0G3q9QNGwij/uaLxI42q6l5ZjoKlg4FZmZOeZoXLAcQA+oly4QgEp3I3tm07qSj 470R9ZLo1Yr4QReGZJO0TNDM4giwdWKxZ1VYnDT6kADKBz+gY2H5jO847yNrWJ4x 2OIsccMA67+C4DvokRMHAKko9dZQZBt5+fHZkNhvbVWN6fldittPnHoIX+zHC+ep ninbsINr3YOX8baNfLmnqMuX3/4bVWQuZPRyIDsCCVyYzfjeTlnx5svePeIJD7vk 1up5Rfbf8YUKkXuKhm7rZMTBOG/AQBvZT/BkVn94M+P9lGyLMk3CMMgSuHnNYFXP H0Sg89R6SkHtdm/bjqy9XLwE6ZWrzIM1C6MBlWLQXg5P6bK0NWhkTY0nDraf0BNC a/FynXlBckSuu1r2yGoP8Ubt7NBpMPgBEOrVr6QxSlZtqQXqO8/jzT7iLlGGmG5k AQNCEsbHF41uUgLGS3JQ =ZifM -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for subscription-manager is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: subscription-manager security update Advisory ID: RHSA-2023:4702-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4702 Issue date: 2023-08-22 CVE Names: CVE-2023-3899 ===================================================================== 1. Summary: An update for subscription-manager is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS E4S (v. 8.1) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: The subscription-manager packages provide programs and libraries to allow users to manage subscriptions and yum repositories from the Red Hat entitlement platform. Security Fix(es): * subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration (CVE-2023-3899) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2225407 - CVE-2023-3899 subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration 6. Package List: Red Hat Enterprise Linux AppStream E4S (v.8.1): aarch64: dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.aarch64.rpm python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.aarch64.rpm rhsm-gtk-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-debuginfo-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-debugsource-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-initial-setup-addon-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-migration-1.25.17.1-2.el8_1.aarch64.rpm ppc64le: dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm rhsm-gtk-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-debugsource-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-initial-setup-addon-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-migration-1.25.17.1-2.el8_1.ppc64le.rpm s390x: dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.s390x.rpm python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.s390x.rpm rhsm-gtk-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-debuginfo-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-debugsource-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-initial-setup-addon-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-migration-1.25.17.1-2.el8_1.s390x.rpm x86_64: dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm rhsm-gtk-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-debugsource-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-initial-setup-addon-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-migration-1.25.17.1-2.el8_1.x86_64.rpm Red Hat Enterprise Linux BaseOS E4S (v.8.1): Source: subscription-manager-1.25.17.1-2.el8_1.src.rpm aarch64: dnf-plugin-subscription-manager-1.25.17.1-2.el8_1.aarch64.rpm dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.aarch64.rpm python3-subscription-manager-rhsm-1.25.17.1-2.el8_1.aarch64.rpm python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.aarch64.rpm python3-syspurpose-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-debuginfo-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-debugsource-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-plugin-container-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-plugin-ostree-1.25.17.1-2.el8_1.aarch64.rpm subscription-manager-rhsm-certificates-1.25.17.1-2.el8_1.aarch64.rpm noarch: subscription-manager-cockpit-1.25.17.1-2.el8_1.noarch.rpm ppc64le: dnf-plugin-subscription-manager-1.25.17.1-2.el8_1.ppc64le.rpm dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm python3-subscription-manager-rhsm-1.25.17.1-2.el8_1.ppc64le.rpm python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm python3-syspurpose-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-debugsource-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-plugin-container-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-plugin-ostree-1.25.17.1-2.el8_1.ppc64le.rpm subscription-manager-rhsm-certificates-1.25.17.1-2.el8_1.ppc64le.rpm s390x: dnf-plugin-subscription-manager-1.25.17.1-2.el8_1.s390x.rpm dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.s390x.rpm python3-subscription-manager-rhsm-1.25.17.1-2.el8_1.s390x.rpm python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.s390x.rpm python3-syspurpose-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-debuginfo-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-debugsource-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-plugin-container-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-plugin-ostree-1.25.17.1-2.el8_1.s390x.rpm subscription-manager-rhsm-certificates-1.25.17.1-2.el8_1.s390x.rpm x86_64: dnf-plugin-subscription-manager-1.25.17.1-2.el8_1.x86_64.rpm dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm python3-subscription-manager-rhsm-1.25.17.1-2.el8_1.x86_64.rpm python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm python3-syspurpose-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-debugsource-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-plugin-container-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-plugin-ostree-1.25.17.1-2.el8_1.x86_64.rpm subscription-manager-rhsm-certificates-1.25.17.1-2.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-3899 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk5RhvAAoJENzjgjWX9erEN+EQAJo3v5YKy3qaOBfRRmAX6ZYn KJRlkjj2kFvolzA1rPyCQIyEQvjgeYi3KYED4Orik1zIKrlFGnRkAQqhmXHCtD+V Vg0HFNp8ZcU8zMs/DKUQ/Kg+PozOF68ZtitYZTycXWeCb9ntcAZ9H9IeSFy+Bt9f MZeblCi3etxpozUIOAn5Bb5NkxHyvl407lMUy5jp1O0PWDcHfp3VnBlKQ394n6ec Ijy9N+fvIqJVaDPjLEcvoDoda8Cw14ZO5EGTAeXvHtvYkFsGYr85d9UvKp4jvKqj X/FEJS8rAO0D0h8Bht3spKHB4pOarcDVJWmWKJVJmVYk59CPGfDLkrSrsRtCqUC+ N5we8pT8Kg6nJe2eUtF0EbaksaZsOxMXgARmO7g2GhAOKn1dMbnzLQ7f9V/6UIsy mKBn4GoVXGLoUw7Ek+h7ca+IqyWdARsxEkzBv3RzeSLt0TsMdgYeaRBwGaKCe9r2 pPoUmGPWSYYfodwSsmKZ8GJI8w7kQ7qCkf9aqNr7FdLXGvHGdueNk7WDc3gkWEgp jQSghH5cgxVneRtpvj9w4v42ibzmd+zMkhOucBgr53ArdixT8argK96MrJcFEGPt Cxw3LEyM+FQnRVwIiFzDcNPh7dglPDamvkiich86U+xKnx5zSQB758Rhr+0bUvXQ Fn9k/ZqhPUSiJcTKfoTE =qpjp -----END PGP SIGNATURE----- -- RHSA-announce mailing list
A security update is now available for Red Hat Single Sign-On 7.5 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Single Sign-On 7.5.0 security update Advisory ID: RHSA-2021:5217-01 Product: Red Hat Single Sign-On Advisory URL: https://access.redhat.com/errata/RHSA-2021:5217 Issue date: 2021-12-20 CVE Names: CVE-2021-4133 ==================================================================== 1. Summary: A security update is now available for Red Hat Single Sign-On 7.5 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Single Sign-On 7.5 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This is an asynchronous patch for Red Hat Single Sign-On 7.5, and includes one security fix. Security Fix: * keycloak: Incorrect authorization allows unpriviledged users to create other users (CVE-2021-4133) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed(https://bugzilla.redhat.com/): 2033602 - CVE-2021-4133 Keycloak: Incorrect authorization allows unpriviledged users to create other users 5. References: https://access.redhat.com/security/cve/CVE-2021-4133 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=core.service.rhsso&version=7.5 https://docs.redhat.com/en/documentation/red_hat_single_sign-on/7.5 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYcDdrdzjgjWX9erEAQjIyA/+NOfsmKyY+l3oCmhyUKqVoyDkqaBGLGfN ODsJGgUJN7F6LcHr+RhfSrFITOFYofxz+XZ6FY8Rn6JT8Xe0e2Ggd+EgqekYdGHE 0PZdjXNkJ9P/ZGkxHNZ50XvmYlp8h2nDIvgXbw81C14dCKKV7aIB8algcIs6KSdm UBeuLkyOlTm4/poawZJB8H4qOH5lhtYSFN5v7u2Jm4srZVm+uwlTtL9d9SsEjCkW BLqx1neJetUKAjAIgg0fr50uW19Y3pA2uTlxHmWevS6JP7Nux3MaBG9LygtsaZFi FNW5cFVxe7BZDUi94SJ3cF7R5c2dpR/a7h11/glTYvO+Czwk+aeyQi57F6RT0I51 L3JLNzT8tJNZ0DhUB8I23/7Lzdw8qz92x3fFhIO+2AXuTHW5jl3+6euhZ3mO7hm8 4iFY5Fr2KwvCc8kZuuuzrljv6Tetz2tsaZiR0QXEBGoQzSzW4RegQFIhfJxfDfEG leOzKzV25NAypAccd88aJhUYADdAeFDp8EtCtGI1uIQwuBNT+ddh0owcXtXlwtpS 0dflPUWe3FANbnLajbasz+DmwIIct0Ryx41l+LM7n2cFKJl/0k2KWtTzlqy7uQJB /aiT1OGQxLTAhZHjysTSKhSCZ8OQVHnBK3F3LmdQvMAg+o4Sp+AVbs1nWCC6N0qt NZPftayAbQ4=ImuM -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Important: pacemaker security and bug fix update. Date: Wed, 14 Dec 2016 17:42:03 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Scott Reid Subject: Security ERRATA Important: pacemaker on SL7.x x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Important: pacemaker security and bug fix update Advisory ID: SLSA-2016:2614-1 Issue Date: 2016-11-03 CVE Numbers: CVE-2016-7035 -- Security Fix(es): * An authorization flaw was found in Pacemaker, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine. (CVE-2016-7035) Bug Fix(es): * The version of Pacemaker in Scientific Linux 7.3 incorporated an increase in the version number of the remote node protocol. Consequently, cluster nodes running Pacemaker in Scientific Linux 7.3 and remote nodes running earlier versions of Scientific Linux were not able to communicate with each other unless special precautions were taken. This update preserves the rolling upgrade capability. -- SL7 x86_64 pacemaker-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-cli-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-cluster-libs-1.1.15-11.el7_3.2.i686.rpm pacemaker-cluster-libs-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-cts-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-debuginfo-1.1.15-11.el7_3.2.i686.rpm pacemaker-debuginfo-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-doc-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-libs-1.1.15-11.el7_3.2.i686.rpm pacemaker-libs-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-libs-devel-1.1.15-11.el7_3.2.i686.rpm pacemaker-libs-devel-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-nagios-plugins-metadata-1.1.15-11.el7_3.2.x86_64.rpm pacemaker-remote-1.1.15-11.el7_3.2.x86_64.rpm - Scientific Linux Development Team . Significant enhancement released for pacemaker relating to vulnerabilities and corrective actions for SL7.x x86_64 platforms..pacemaker update, important security, SL7 x86_64, authorization flaw, Scientific Linux advisory. . Severity: Important. LinuxSecurity.com Team
Important: pacemaker security update. Date: Tue, 8 Nov 2016 21:20:09 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA Important: pacemaker on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Important: pacemaker security update Advisory ID: SLSA-2016:2675-1 Issue Date: 2016-11-08 CVE Numbers: CVE-2016-7035 -- Security Fix(es): * An authorization flaw was found in Pacemaker, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine. (CVE-2016-7035) This issue was discovered by Jan "poki" Pokorny (Red Hat) and Alain Moulle (ATOS/BULL). -- SL6 x86_64 pacemaker-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cli-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cts-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.i686.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-doc-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-remote-1.1.14-8.el6_8.2.x86_64.rpm i386 pacemaker-1.1.14-8.el6_8.2.i686.rpm pacemaker-cli-1.1.14-8.el6_8.2.i686.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-cts-1.1.14-8.el6_8.2.i686.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.i686.rpm pacemaker-doc-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.i686.rpm pacemaker-remote-1.1.14-8.el6_8.2.i686.rpm - Scientific Linux Development Team . Critical alert for Scientific Linux resolving vulnerabilities in Pacemaker's authorization on SL6.x.. pacemaker security update, Scientific Linux update,authorization flaw, security advisory. . Severity: Important. LinuxSecurity.com Team
An update for pacemaker is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: pacemaker security update Advisory ID: RHSA-2016:2675-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:2675.html Issue date: 2016-11-08 CVE Names: CVE-2016-7035 ==================================================================== 1. Summary: An update for pacemaker is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux High Availability (v. 6) - i386, x86_64 Red Hat Enterprise Linux Resilient Storage (v. 6) - i386, x86_64 3. Description: The Pacemaker cluster resource manager is a collection of technologies working together to provide data integrity and the ability to maintain application availability in the event of a failure. Security Fix(es): * An authorization flaw was found in Pacemaker, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine. (CVE-2016-7035) This issue was discovered by Jan "poki" Pokorny (Red Hat) and Alain Moulle (ATOS/BULL). 4. Solution: For details on how to apply this update, which includes thechanges described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1369732 - CVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication 6. Package List: Red Hat Enterprise Linux High Availability (v. 6): Source: pacemaker-1.1.14-8.el6_8.2.src.rpm i386: pacemaker-1.1.14-8.el6_8.2.i686.rpm pacemaker-cli-1.1.14-8.el6_8.2.i686.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-cts-1.1.14-8.el6_8.2.i686.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.i686.rpm pacemaker-doc-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.i686.rpm pacemaker-remote-1.1.14-8.el6_8.2.i686.rpm x86_64: pacemaker-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cli-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cts-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.i686.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-doc-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-remote-1.1.14-8.el6_8.2.x86_64.rpm Red Hat Enterprise Linux Resilient Storage (v.6): Source: pacemaker-1.1.14-8.el6_8.2.src.rpm i386: pacemaker-1.1.14-8.el6_8.2.i686.rpm pacemaker-cli-1.1.14-8.el6_8.2.i686.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-cts-1.1.14-8.el6_8.2.i686.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.i686.rpm pacemaker-doc-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.i686.rpm pacemaker-remote-1.1.14-8.el6_8.2.i686.rpm x86_64: pacemaker-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cli-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-cluster-libs-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-cts-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.i686.rpm pacemaker-debuginfo-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-doc-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-libs-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.i686.rpm pacemaker-libs-devel-1.1.14-8.el6_8.2.x86_64.rpm pacemaker-remote-1.1.14-8.el6_8.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2016-7035 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYIdG8XlSAg2UNWIIRAvbRAJ9KzQyVw3sR4cxpwuU2WVD6Vd//lQCfWAm+ JVLa5gTCTNzPdNOTAT4L4Y8=vZiQ -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.