RHSA-2019:1222MediumCVSS 7.6

Red Hat Security Advisory: Satellite 6.5 Release

Published
May 14, 2019
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2016-6346 — RESTEasy: Abuse of GZIPInterceptor in RESTEasy can lead to denial of service attack CVE-2018-10917 — pulp: Improper path parsing leads to overwriting of iso repositories CVE-2018-14664 — foreman: Persisted XSS on all pages that use breadcrumbs CVE-2018-16861 — foreman: stored XSS in success notification after entity creation CVE-2018-16887 — katello: stored XSS in subscriptions and repositories pages CVE-2019-3891 — candlepin: credentials exposure through log files

🎯 Affected products200

  • Red Hat Satellite 6.5
  • Red Hat Satellite Capsule 6.5
  • SOAPpy-0:0.11.6-17.el7.noarch as a component of Red Hat Satellite 6.5
  • SOAPpy-0:0.11.6-17.el7.noarch as a component of Red Hat Satellite Capsule 6.5
  • SOAPpy-0:0.11.6-17.el7.src as a component of Red Hat Satellite 6.5
  • SOAPpy-0:0.11.6-17.el7.src as a component of Red Hat Satellite Capsule 6.5
  • ansiblerole-insights-client-0:1.6-1.el7sat.noarch as a component of Red Hat Satellite 6.5
  • ansiblerole-insights-client-0:1.6-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.5
  • ansiblerole-insights-client-0:1.6-1.el7sat.src as a component of Red Hat Satellite 6.5
  • ansiblerole-insights-client-0:1.6-1.el7sat.src as a component of Red Hat Satellite Capsule 6.5
  • candlepin-0:2.5.15-1.el7sat.noarch as a component of Red Hat Satellite 6.5
  • candlepin-0:2.5.15-1.el7sat.src as a component of Red Hat Satellite 6.5
  • candlepin-selinux-0:2.5.15-1.el7sat.noarch as a component of Red Hat Satellite 6.5
  • createrepo_c-0:0.7.4-1.el7sat.src as a component of Red Hat Satellite 6.5
  • createrepo_c-0:0.7.4-1.el7sat.src as a component of Red Hat Satellite Capsule 6.5
  • createrepo_c-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.5
  • createrepo_c-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.5
  • createrepo_c-debuginfo-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.5
  • createrepo_c-debuginfo-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.5
  • createrepo_c-libs-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.5
  • createrepo_c-libs-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.5
  • foreman-0:1.20.1.34-1.el7sat.noarch as a component of Red Hat Satellite 6.5
  • foreman-0:1.20.1.34-1.el7sat.src as a component of Red Hat Satellite 6.5
  • foreman-0:1.20.1.34-1.el7sat.src as a component of Red Hat Satellite Capsule 6.5
  • foreman-bootloaders-redhat-0:201801241201-4.el7sat.noarch as a component of Red Hat Satellite 6.5
  • foreman-bootloaders-redhat-0:201801241201-4.el7sat.noarch as a component of Red Hat Satellite Capsule 6.5
  • foreman-bootloaders-redhat-0:201801241201-4.el7sat.src as a component of Red Hat Satellite 6.5
  • foreman-bootloaders-redhat-0:201801241201-4.el7sat.src as a component of Red Hat Satellite Capsule 6.5
  • foreman-bootloaders-redhat-tftpboot-0:201801241201-4.el7sat.noarch as a component of Red Hat Satellite 6.5
  • foreman-bootloaders-redhat-tftpboot-0:201801241201-4.el7sat.noarch as a component of Red Hat Satellite Capsule 6.5
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Remove world readable permission from /var/log/candlepin/cpdb.log, by executing the following on the console of the machine where Red Hat Satellite is installed, as root: chmod o-r /var/log/candlepin/cpdb.log

🔗 References (472)