Red Hat Security Advisory: idm:DL1 and idm:client security, bug fix, and enhancement update
🔗 CVE IDs covered (10)
📋 Description
CVE-2015-9251 — jquery: Cross-site scripting via cross-domain ajax requests CVE-2016-10735 — bootstrap: XSS in the data-target attribute CVE-2018-14040 — bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute CVE-2018-14042 — bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip CVE-2018-20676 — bootstrap: XSS in the tooltip data-viewport attribute CVE-2018-20677 — bootstrap: XSS in the affix configuration target property CVE-2019-8331 — bootstrap: XSS in the tooltip or popover data-template attribute CVE-2019-11358 — jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection CVE-2020-1722 — ipa: No password length restriction leads to denial of service CVE-2020-11022 — jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
🎯 Affected products166
- Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.3-1.module+el8.3.0+6993+104f8db0.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.3-1.module+el8.3.0+6993+104f8db0.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.3-1.module+el8.3.0+6993+104f8db0.s390x (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.3-1.module+el8.3.0+6993+104f8db0.src (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.3-1.module+el8.3.0+6993+104f8db0.x86_64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debuginfo-0:11.3-1.module+el8.3.0+6993+104f8db0.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debuginfo-0:11.3-1.module+el8.3.0+6993+104f8db0.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debuginfo-0:11.3-1.module+el8.3.0+6993+104f8db0.s390x (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debuginfo-0:11.3-1.module+el8.3.0+6993+104f8db0.x86_64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debugsource-0:11.3-1.module+el8.3.0+6993+104f8db0.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debugsource-0:11.3-1.module+el8.3.0+6993+104f8db0.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debugsource-0:11.3-1.module+el8.3.0+6993+104f8db0.s390x (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debugsource-0:11.3-1.module+el8.3.0+6993+104f8db0.x86_64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- custodia-0:0.6.0-3.module+el8.1.0+4098+f286395e.noarch (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- custodia-0:0.6.0-3.module+el8.1.0+4098+f286395e.src (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-0:4.8.7-12.module+el8.3.0+8222+c1bff54a.src (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-0:4.8.7-12.module+el8.3.0+8223+6212645f.src (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.8.7-12.module+el8.3.0+8222+c1bff54a.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.8.7-12.module+el8.3.0+8222+c1bff54a.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.8.7-12.module+el8.3.0+8222+c1bff54a.s390x (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.8.7-12.module+el8.3.0+8222+c1bff54a.x86_64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.8.7-12.module+el8.3.0+8223+6212645f.aarch64 (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.8.7-12.module+el8.3.0+8223+6212645f.ppc64le (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.8.7-12.module+el8.3.0+8223+6212645f.s390x (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.8.7-12.module+el8.3.0+8223+6212645f.x86_64 (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-common-0:4.8.7-12.module+el8.3.0+8222+c1bff54a.noarch (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-common-0:4.8.7-12.module+el8.3.0+8223+6212645f.noarch (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-debuginfo-0:4.8.7-12.module+el8.3.0+8222+c1bff54a.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-debuginfo-0:4.8.7-12.module+el8.3.0+8222+c1bff54a.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +136 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (64)
- selfhttps://access.redhat.com/errata/RHSA-2020:4670
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1399546
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1430365
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1488732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1585020
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601614
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1651577
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668082
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1686454
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1701233
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1701972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1746830
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1750893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1751295
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1757045
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1759888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1768156
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1777806
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1793071
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1801698
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802471
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1809835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1810154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1810179
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1813330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1818765
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1818877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1831732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1831935
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1832331
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1833266
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1834264
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1834909
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1845211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1845537
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1845596
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1846352
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1846434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1847999
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1849914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851411
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1852244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1853263
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857157
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1858318
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1859213
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1863079
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1863616
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1866291
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1866938
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1868432
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1869311
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1870202
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1874015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1875348
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879604
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4670.json