QID 239228
Date Published: 2021-05-10
QID 239228: Red Hat Update for Satellite 6.9 (RHSA-2021:1313)
Red Hat Satellite is a systems management tool for Linux-basedinfrastructure. It allows for provisioning, remote management, andmonitoring of multiple Linux deployments with a single centralized tool.
Security Fix(es): foreman: Managing repositories with their id via hammer does not respect the role filters (CVE-2017-2662)
python-psutil: Double free because of refcount mishandling (CVE-2019-18874)
candlepin: netty: compression/decompression codecs don't enforce limits on buffer allocation sizes (CVE-2020-11612)
foreman: world-readable OMAPI secret through the ISC DHCP server (CVE-2020-14335)
candlepin: resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling (CVE-2020-25633)
python-django: potential SQL injection via "tolerance" parameter in GIS functions and aggregates on Oracle (CVE-2020-9402)
Affected Products:
Red Hat Satellite 6.9 x86_64
Red Hat Satellite Capsule 6.9 x86_64
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
On successful exploitation, it could allow an attacker to execute code.
Refer to Red Hat security advisory RHSA-2021:1313 to address this issue and obtain more information.
- RHSA-2021:1313 -
access.redhat.com/errata/RHSA-2021:1313?language=en
CVEs related to QID 239228
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| RHSA-2021:1313 | Red Hat Enterprise Linux |
|