Red Hat Security Advisory: security update - Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container
🔗 CVE IDs covered (6)
📋 Description
CVE-2019-18874 — python-psutil: Double free because of refcount mishandling CVE-2020-7676 — nodejs-angular: XSS due to regex-based HTML replacement CVE-2020-7720 — nodejs-node-forge: prototype pollution via the util.setPath function CVE-2020-7743 — mathjs: prototype pollution via the deepExtend function that runs upon configuration updates CVE-2020-11022 — jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods
🎯 Affected products2
- Red Hat Ansible Tower 3.7 for RHEL 7
- ansible-tower-37/ansible-tower-rhel7@sha256:46d02d82c8b89dc22259fd4d8ea2febd9c64427239806da48f97b0c96be157e5_amd64 as a component of Red Hat Ansible Tower 3.7 for RHEL 7
✅ Remediation
For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://docs.ansible.com/ansible-tower/latest/html/upgrade-migration-guide/index.html Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2020:5249
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1850004
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_5249.json