Red Hat Bug Fix Advisory: Satellite 6.7.2 Async Bug Fix Update
🔗 CVE IDs covered (12)
📋 Description
CVE-2019-20330 — jackson-databind: lacks certain net.sf.ehcache blocking CVE-2020-8840 — jackson-databind: Lacks certain xbean-reflect/JNDI blocking CVE-2020-9546 — jackson-databind: Serialization gadgets in shaded-hikari-config CVE-2020-9547 — jackson-databind: Serialization gadgets in ibatis-sqlmap CVE-2020-9548 — jackson-databind: Serialization gadgets in anteros-core CVE-2020-10968 — jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvider CVE-2020-10969 — jackson-databind: Serialization gadgets in javax.swing.JEditorPane CVE-2020-11619 — jackson-databind: Serialization gadgets in org.springframework:spring-aop CVE-2020-14060 — jackson-databind: serialization in oadd.org.apache.xalan.lib.sql.JNDIConnectionPool CVE-2020-14061 — jackson-databind: serialization in weblogic/oracle-aqjms CVE-2020-14062 — jackson-databind: serialization in com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool CVE-2020-14195 — jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory
🎯 Affected products60
- Red Hat Satellite 6.7
- Red Hat Satellite Capsule 6.7
- candlepin-0:2.9.28-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- candlepin-0:2.9.28-1.el7sat.src as a component of Red Hat Satellite 6.7
- candlepin-selinux-0:2.9.28-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-0:1.24.1.24-1.el7sat.src as a component of Red Hat Satellite 6.7
- foreman-0:1.24.1.24-1.el7sat.src as a component of Red Hat Satellite Capsule 6.7
- foreman-cli-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-debug-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-debug-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.7
- foreman-ec2-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-gce-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-installer-1:1.24.1.21-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-installer-1:1.24.1.21-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.7
- foreman-installer-1:1.24.1.21-1.el7sat.src as a component of Red Hat Satellite 6.7
- foreman-installer-1:1.24.1.21-1.el7sat.src as a component of Red Hat Satellite Capsule 6.7
- foreman-installer-katello-1:1.24.1.21-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-installer-katello-1:1.24.1.21-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.7
- foreman-journald-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-libvirt-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-openstack-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-ovirt-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-postgresql-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-rackspace-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-telemetry-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- foreman-vmware-0:1.24.1.24-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- pulp-rpm-0:2.21.0.6-1.el7sat.src as a component of Red Hat Satellite 6.7
- pulp-rpm-0:2.21.0.6-1.el7sat.src as a component of Red Hat Satellite Capsule 6.7
- pulp-rpm-admin-extensions-0:2.21.0.6-1.el7sat.noarch as a component of Red Hat Satellite 6.7
- +30 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.7/html/upgrading_and_updating_red_hat_satellite/updating_satellite_server_capsule_server_and_content_hosts Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * enableDefaultTyping() * @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS * oadd.org.apache.xalan.lib.sql.JNDIConnectionPool in classpath Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * enableDefaultTyping() * @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS * oracle.jms.AQjms*ConnectionFactory in classpath Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * enableDefaultTyping() * @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS * com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool in classpath Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * enableDefaultTyping() * @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS * org.jsecurity.realm.jndi.JndiRealmFactory in classpath
🔗 References (27)
- selfhttps://access.redhat.com/errata/RHBA-2020:3255
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1832581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1839970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851128
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851130
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851132
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851134
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851136
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851137
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851138
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851140
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851141
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851148
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851149
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851151
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851157
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851158
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851159
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851160
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851163
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1854824
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856834
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857359
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhba-2020_3255.json