RHSA-2024:0137
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: idm:DL1 security update
CVSS Metrics
- v3.1•HIGH•Score: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•bind-dyndb-ldap
< 0:11.6-4.module+el8.8.0+17351+9a3fb056
- redhat•bind-dyndb-ldap-debuginfo
< 0:11.6-4.module+el8.8.0+17351+9a3fb056
- redhat•bind-dyndb-ldap-debugsource
< 0:11.6-4.module+el8.8.0+17351+9a3fb056
- redhat•custodia
< 0:0.6.0-3.module+el8.1.0+4098+f286395e
- redhat•ipa
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-client
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-client-common
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-client-debuginfo
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-client-epn
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-client-samba
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-common
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-debuginfo
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-debugsource
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-healthcheck
< 0:0.12-1.module+el8.8.0+17582+6bf5bf91
- redhat•ipa-healthcheck-core
< 0:0.12-1.module+el8.8.0+17582+6bf5bf91
- redhat•ipa-python-compat
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-selinux
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-server
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-server-common
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-server-debuginfo
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-server-dns
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-server-trust-ad
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•ipa-server-trust-ad-debuginfo
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•opendnssec
< 0:2.1.7-1.module+el8.4.0+9007+5084bdd8
- redhat•opendnssec-debuginfo
< 0:2.1.7-1.module+el8.4.0+9007+5084bdd8
- redhat•opendnssec-debugsource
< 0:2.1.7-1.module+el8.4.0+9007+5084bdd8
- redhat•python-jwcrypto
< 0:0.5.0-1.1.module+el8.7.0+15842+306cbc83
- redhat•python-kdcproxy
< 0:0.4-5.module+el8.2.0+4691+a05b2456
- redhat•python-qrcode
< 0:5.1-12.module+el8.1.0+4098+f286395e
- redhat•python-yubico
< 0:1.3.2-9.1.module+el8.7.0+15691+2b2c1dd5
- redhat•python3-custodia
< 0:0.6.0-3.module+el8.1.0+4098+f286395e
- redhat•python3-ipaclient
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•python3-ipalib
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•python3-ipaserver
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•python3-ipatests
< 0:4.9.11-9.module+el8.8.0+20825+52dd1628
- redhat•python3-jwcrypto
< 0:0.5.0-1.1.module+el8.7.0+15842+306cbc83
- redhat•python3-kdcproxy
< 0:0.4-5.module+el8.2.0+4691+a05b2456
- redhat•python3-pyusb
< 0:1.0.0-9.1.module+el8.7.0+15691+2b2c1dd5
- redhat•python3-qrcode
< 0:5.1-12.module+el8.1.0+4098+f286395e
- redhat•python3-qrcode-core
< 0:5.1-12.module+el8.1.0+4098+f286395e
- redhat•python3-yubico
< 0:1.3.2-9.1.module+el8.7.0+15691+2b2c1dd5
- redhat•pyusb
< 0:1.0.0-9.1.module+el8.7.0+15691+2b2c1dd5
- redhat•slapi-nis
< 0:0.60.0-4.module+el8.8.0+20635+330e3683
- redhat•slapi-nis-debuginfo
< 0:0.60.0-4.module+el8.8.0+20635+330e3683
- redhat•slapi-nis-debugsource
< 0:0.60.0-4.module+el8.8.0+20635+330e3683
- redhat•softhsm
< 0:2.6.0-5.module+el8.4.0+10227+076cd560
- redhat•softhsm-debuginfo
< 0:2.6.0-5.module+el8.4.0+10227+076cd560
- redhat•softhsm-debugsource
< 0:2.6.0-5.module+el8.4.0+10227+076cd560
- redhat•softhsm-devel
< 0:2.6.0-5.module+el8.4.0+10227+076cd560
References (16)
- https://access.redhat.com/errata/RHSA-2024:0137
- https://access.redhat.com/security/updates/classification/#moderate
- https://bugzilla.redhat.com/show_bug.cgi?id=2025721
- https://bugzilla.redhat.com/show_bug.cgi?id=2242828
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0137.json
- https://access.redhat.com/security/cve/CVE-2020-17049
- https://www.cve.org/CVERecord?id=CVE-2020-17049
- https://nvd.nist.gov/vuln/detail/CVE-2020-17049
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-17049
- https://access.redhat.com/security/cve/CVE-2023-5455
- https://www.cve.org/CVERecord?id=CVE-2023-5455
- https://nvd.nist.gov/vuln/detail/CVE-2023-5455
- https://www.freeipa.org/release-notes/4-10-3.html
- https://www.freeipa.org/release-notes/4-11-1.html
- https://www.freeipa.org/release-notes/4-6-10.html
- https://www.freeipa.org/release-notes/4-9-14.html