Red Hat Security Advisory: ipa security, bug fix, and enhancement update
🔗 CVE IDs covered (10)
📋 Description
CVE-2015-9251 — jquery: Cross-site scripting via cross-domain ajax requests CVE-2016-10735 — bootstrap: XSS in the data-target attribute CVE-2018-14040 — bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute CVE-2018-14042 — bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip CVE-2018-20676 — bootstrap: XSS in the tooltip data-viewport attribute CVE-2018-20677 — bootstrap: XSS in the affix configuration target property CVE-2019-8331 — bootstrap: XSS in the tooltip or popover data-template attribute CVE-2019-11358 — jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection CVE-2020-1722 — ipa: No password length restriction leads to denial of service CVE-2020-11022 — jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
🎯 Affected products66
- Red Hat Enterprise Linux Client (v. 7)
- Red Hat Enterprise Linux Client Optional (v. 7)
- Red Hat Enterprise Linux ComputeNode (v. 7)
- Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- Red Hat Enterprise Linux Server (v. 7)
- Red Hat Enterprise Linux Workstation (v. 7)
- ipa-0:4.6.8-5.el7.src as a component of Red Hat Enterprise Linux Client (v. 7)
- ipa-0:4.6.8-5.el7.src as a component of Red Hat Enterprise Linux ComputeNode (v. 7)
- ipa-0:4.6.8-5.el7.src as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-0:4.6.8-5.el7.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
- ipa-client-0:4.6.8-5.el7.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-client-0:4.6.8-5.el7.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-client-0:4.6.8-5.el7.s390x as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-client-0:4.6.8-5.el7.x86_64 as a component of Red Hat Enterprise Linux Client (v. 7)
- ipa-client-0:4.6.8-5.el7.x86_64 as a component of Red Hat Enterprise Linux ComputeNode (v. 7)
- ipa-client-0:4.6.8-5.el7.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-client-0:4.6.8-5.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation (v. 7)
- ipa-client-common-0:4.6.8-5.el7.noarch as a component of Red Hat Enterprise Linux Client (v. 7)
- ipa-client-common-0:4.6.8-5.el7.noarch as a component of Red Hat Enterprise Linux ComputeNode (v. 7)
- ipa-client-common-0:4.6.8-5.el7.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-client-common-0:4.6.8-5.el7.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- ipa-common-0:4.6.8-5.el7.noarch as a component of Red Hat Enterprise Linux Client (v. 7)
- ipa-common-0:4.6.8-5.el7.noarch as a component of Red Hat Enterprise Linux ComputeNode (v. 7)
- ipa-common-0:4.6.8-5.el7.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-common-0:4.6.8-5.el7.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- ipa-debuginfo-0:4.6.8-5.el7.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-debuginfo-0:4.6.8-5.el7.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-debuginfo-0:4.6.8-5.el7.s390x as a component of Red Hat Enterprise Linux Server (v. 7)
- ipa-debuginfo-0:4.6.8-5.el7.x86_64 as a component of Red Hat Enterprise Linux Client (v. 7)
- ipa-debuginfo-0:4.6.8-5.el7.x86_64 as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- +36 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (39)
- selfhttps://access.redhat.com/errata/RHSA-2020:3936
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.9_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1399546
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1404770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1545755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601614
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668082
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1686454
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1701972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1754902
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1755535
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1756568
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1758406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1769791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1771356
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1780548
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1782587
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1788718
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1788907
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1793071
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1795890
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1801791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817886
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817918
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817919
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817922
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817923
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1819725
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1825829
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1829787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1834385
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1842950
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3936.json