Red Hat Bug Fix Advisory: Satellite 6.6.3 Async Bug Fix Update
🔗 CVE IDs covered (13)
📋 Description
CVE-2019-12086 — jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server. CVE-2019-20330 — jackson-databind: lacks certain net.sf.ehcache blocking CVE-2020-8840 — jackson-databind: Lacks certain xbean-reflect/JNDI blocking CVE-2020-9546 — jackson-databind: Serialization gadgets in shaded-hikari-config CVE-2020-9547 — jackson-databind: Serialization gadgets in ibatis-sqlmap CVE-2020-9548 — jackson-databind: Serialization gadgets in anteros-core CVE-2020-10968 — jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvider CVE-2020-10969 — jackson-databind: Serialization gadgets in javax.swing.JEditorPane CVE-2020-11619 — jackson-databind: Serialization gadgets in org.springframework:spring-aop CVE-2020-14060 — jackson-databind: serialization in oadd.org.apache.xalan.lib.sql.JNDIConnectionPool CVE-2020-14061 — jackson-databind: serialization in weblogic/oracle-aqjms CVE-2020-14062 — jackson-databind: serialization in com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool CVE-2020-14195 — jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory
🎯 Affected products39
- Red Hat Satellite 6.6
- Red Hat Satellite Capsule 6.6
- candlepin-0:2.6.16-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- candlepin-0:2.6.16-1.el7sat.src as a component of Red Hat Satellite 6.6
- candlepin-selinux-0:2.6.16-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-0:1.22.0.39-2.el7sat.src as a component of Red Hat Satellite 6.6
- foreman-0:1.22.0.39-2.el7sat.src as a component of Red Hat Satellite Capsule 6.6
- foreman-cli-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-debug-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-debug-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
- foreman-ec2-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-gce-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-journald-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-libvirt-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-openstack-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-ovirt-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-postgresql-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-rackspace-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-telemetry-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- foreman-vmware-0:1.22.0.39-2.el7sat.noarch as a component of Red Hat Satellite 6.6
- satellite-0:6.6.3-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- satellite-0:6.6.3-1.el7sat.src as a component of Red Hat Satellite 6.6
- satellite-0:6.6.3-1.el7sat.src as a component of Red Hat Satellite Capsule 6.6
- satellite-capsule-0:6.6.3-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- satellite-capsule-0:6.6.3-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
- satellite-cli-0:6.6.3-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- satellite-common-0:6.6.3-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- satellite-common-0:6.6.3-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
- satellite-debug-tools-0:6.6.3-1.el7sat.noarch as a component of Red Hat Satellite 6.6
- +9 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.6/html/upgrading_and_updating_red_hat_satellite/updating_satellite_server_capsule_server_and_content_hosts Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * enableDefaultTyping() * @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS * oadd.org.apache.xalan.lib.sql.JNDIConnectionPool in classpath Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * enableDefaultTyping() * @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS * oracle.jms.AQjms*ConnectionFactory in classpath Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * enableDefaultTyping() * @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS * com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool in classpath Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * enableDefaultTyping() * @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS * org.jsecurity.realm.jndi.JndiRealmFactory in classpath
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHBA-2020:1494
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812592
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814424
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814425
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814427
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814428
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1818940
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1819911
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhba-2020_1494.json