RHSA-2023:7851
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Satellite 6.14.1 Async Security Update
CVSS Metrics
- v3.1•MEDIUM•Score: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•createrepo_c
< 0:1.0.2-2.el8pc
- redhat•createrepo_c-debuginfo
< 0:1.0.2-2.el8pc
- redhat•createrepo_c-debugsource
< 0:1.0.2-2.el8pc
- redhat•createrepo_c-libs
< 0:1.0.2-2.el8pc
- redhat•createrepo_c-libs-debuginfo
< 0:1.0.2-2.el8pc
- redhat•foreman
< 0:3.7.0.10-1.el8sat
- redhat•foreman-cli
< 0:3.7.0.10-1.el8sat
- redhat•foreman-debug
< 0:3.7.0.10-1.el8sat
- redhat•foreman-dynflow-sidekiq
< 0:3.7.0.10-1.el8sat
- redhat•foreman-ec2
< 0:3.7.0.10-1.el8sat
- redhat•foreman-installer
< 1:3.7.0.5-1.el8sat
- redhat•foreman-installer-katello
< 1:3.7.0.5-1.el8sat
- redhat•foreman-journald
< 0:3.7.0.10-1.el8sat
- redhat•foreman-libvirt
< 0:3.7.0.10-1.el8sat
- redhat•foreman-openstack
< 0:3.7.0.10-1.el8sat
- redhat•foreman-ovirt
< 0:3.7.0.10-1.el8sat
- redhat•foreman-postgresql
< 0:3.7.0.10-1.el8sat
- redhat•foreman-redis
< 0:3.7.0.10-1.el8sat
- redhat•foreman-service
< 0:3.7.0.10-1.el8sat
- redhat•foreman-telemetry
< 0:3.7.0.10-1.el8sat
- redhat•foreman-vmware
< 0:3.7.0.10-1.el8sat
- redhat•pulpcore-selinux
< 0:2.0.0-1.el8pc
- redhat•python-django-import-export
< 0:3.1.0-1.el8pc
- redhat•python-gitpython
< 0:3.1.40-0.1.el8pc
- redhat•python-pulp-rpm
< 0:3.19.11-2.el8pc
- redhat•python-pulpcore
< 0:3.22.19-1.el8pc
- redhat•python-urllib3
< 0:1.26.18-0.1.el8pc
- redhat•python3-createrepo_c
< 0:1.0.2-2.el8pc
- redhat•python3-createrepo_c-debuginfo
< 0:1.0.2-2.el8pc
- redhat•python39-createrepo_c
< 0:1.0.2-2.el8pc
- redhat•python39-createrepo_c-debuginfo
< 0:1.0.2-2.el8pc
- redhat•python39-django-import-export
< 0:3.1.0-1.el8pc
- redhat•python39-gitpython
< 0:3.1.40-0.1.el8pc
- redhat•python39-pulp-rpm
< 0:3.19.11-2.el8pc
- redhat•python39-pulpcore
< 0:3.22.19-1.el8pc
- redhat•python39-urllib3
< 0:1.26.18-0.1.el8pc
- redhat•rubygem-actioncable
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-actionmailbox
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-actionmailer
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-actionpack
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-actiontext
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-actionview
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-activejob
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-activemodel
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-activerecord
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-activestorage
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-activesupport
< 0:6.1.7.4-1.el8sat
- redhat•rubygem-foreman_leapp
< 0:1.1.0-1.el8sat
- redhat•rubygem-foreman_remote_execution
< 0:10.1.2-1.el8sat
- redhat•rubygem-foreman_remote_execution-cockpit
< 0:10.1.2-1.el8sat
Showing first 50 affected entries in server-rendered view.
References (40)
- https://access.redhat.com/errata/RHSA-2023:7851
- https://access.redhat.com/security/updates/classification/#moderate
- https://access.redhat.com/documentation/en-us/red_hat_satellite/6.14/html/upgrading_red_hat_satellite_to_6.14/index
- https://bugzilla.redhat.com/show_bug.cgi?id=2217785
- https://bugzilla.redhat.com/show_bug.cgi?id=2230135
- https://bugzilla.redhat.com/show_bug.cgi?id=2246840
- https://bugzilla.redhat.com/show_bug.cgi?id=2247040
- https://bugzilla.redhat.com/show_bug.cgi?id=2250342
- https://bugzilla.redhat.com/show_bug.cgi?id=2250343
- https://bugzilla.redhat.com/show_bug.cgi?id=2250344
- https://bugzilla.redhat.com/show_bug.cgi?id=2250345
- https://bugzilla.redhat.com/show_bug.cgi?id=2250349
- https://bugzilla.redhat.com/show_bug.cgi?id=2250350
- https://bugzilla.redhat.com/show_bug.cgi?id=2250351
- https://bugzilla.redhat.com/show_bug.cgi?id=2250352
- https://bugzilla.redhat.com/show_bug.cgi?id=2251799
- https://bugzilla.redhat.com/show_bug.cgi?id=2254080
- https://bugzilla.redhat.com/show_bug.cgi?id=2254085
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7851.json
- https://access.redhat.com/security/cve/CVE-2023-4886
- https://www.cve.org/CVERecord?id=CVE-2023-4886
- https://nvd.nist.gov/vuln/detail/CVE-2023-4886
- https://access.redhat.com/security/cve/CVE-2023-28362
- https://www.cve.org/CVERecord?id=CVE-2023-28362
- https://nvd.nist.gov/vuln/detail/CVE-2023-28362
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2023-28362.yml
- https://access.redhat.com/security/cve/CVE-2023-41040
- https://www.cve.org/CVERecord?id=CVE-2023-41040
- https://nvd.nist.gov/vuln/detail/CVE-2023-41040
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-cwvm-v4w8-q58c
- https://access.redhat.com/security/cve/CVE-2023-43804
- https://bugzilla.redhat.com/show_bug.cgi?id=2242493
- https://www.cve.org/CVERecord?id=CVE-2023-43804
- https://nvd.nist.gov/vuln/detail/CVE-2023-43804
- https://access.redhat.com/security/cve/CVE-2023-45803
- https://www.cve.org/CVERecord?id=CVE-2023-45803
- https://nvd.nist.gov/vuln/detail/CVE-2023-45803
- https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9
- https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4
- https://www.rfc-editor.org/rfc/rfc9110.html#name-get