RHSA-2024:10806
Advisory lineage Upstream: 5 Downstream: 0
Published: 05 Dec 2024, 10:02
Last modified:03 Jun 2026, 10:06
Vulnerability Summary
Overall Risk (default)
medium
30/100 CVSS Score
7.4 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
05 Dec 2024, 10:02
Published
Vulnerability first disclosed
03 Jun 2026, 10:06
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Satellite 6.15.5 Async Update
CVSS Metrics
- v3.1•HIGH•Score: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Systems
- redhat•python-pulp-container
< 0:2.16.9-2.el8pc
- redhat•python3.11-pulp-container
< 0:2.16.9-2.el8pc
- redhat•rubygem-activestorage
< 0:6.1.7.7-1.el8sat
- redhat•rubygem-rack
< 0:2.2.8.1-1.el8sat
References (41)
- https://access.redhat.com/errata/RHSA-2024:10806
- https://access.redhat.com/security/updates/classification/#moderate
- https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index
- https://bugzilla.redhat.com/show_bug.cgi?id=2259780
- https://bugzilla.redhat.com/show_bug.cgi?id=2265593
- https://bugzilla.redhat.com/show_bug.cgi?id=2265594
- https://bugzilla.redhat.com/show_bug.cgi?id=2265595
- https://bugzilla.redhat.com/show_bug.cgi?id=2266063
- https://issues.redhat.com/browse/SAT-28466
- https://issues.redhat.com/browse/SAT-28665
- https://issues.redhat.com/browse/SAT-28689
- https://issues.redhat.com/browse/SAT-28690
- https://issues.redhat.com/browse/SAT-28691
- https://issues.redhat.com/browse/SAT-28693
- https://issues.redhat.com/browse/SAT-28695
- https://issues.redhat.com/browse/SAT-28696
- https://issues.redhat.com/browse/SAT-28697
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10806.json
- https://access.redhat.com/security/cve/CVE-2024-23342
- https://www.cve.org/CVERecord?id=CVE-2024-23342
- https://nvd.nist.gov/vuln/detail/CVE-2024-23342
- https://github.com/tlsfuzzer/python-ecdsa/blob/master/SECURITY.md
- https://github.com/tlsfuzzer/python-ecdsa/security/advisories/GHSA-wj6h-64fc-37mp
- https://minerva.crocs.fi.muni.cz/
- https://securitypitfalls.wordpress.com/2018/08/03/constant-time-compare-in-python/
- https://access.redhat.com/security/cve/CVE-2024-25126
- https://www.cve.org/CVERecord?id=CVE-2024-25126
- https://nvd.nist.gov/vuln/detail/CVE-2024-25126
- https://discuss.rubyonrails.org/t/denial-of-service-vulnerability-in-rack-content-type-parsing/84941
- https://access.redhat.com/security/cve/CVE-2024-26141
- https://www.cve.org/CVERecord?id=CVE-2024-26141
- https://nvd.nist.gov/vuln/detail/CVE-2024-26141
- https://discuss.rubyonrails.org/t/possible-dos-vulnerability-with-range-header-in-rack/84944
- https://access.redhat.com/security/cve/CVE-2024-26144
- https://www.cve.org/CVERecord?id=CVE-2024-26144
- https://nvd.nist.gov/vuln/detail/CVE-2024-26144
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2024-26144.yml
- https://access.redhat.com/security/cve/CVE-2024-26146
- https://www.cve.org/CVERecord?id=CVE-2024-26146
- https://nvd.nist.gov/vuln/detail/CVE-2024-26146
- https://discuss.rubyonrails.org/t/possible-denial-of-service-vulnerability-in-rack-header-parsing/84942