RHSA-2021:1313MediumCVSS 8.8

Red Hat Security Advisory: Satellite 6.9 Release

Published
April 21, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (17)

📋 Description

CVE-2015-1820 — rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses CVE-2015-3448 — rubygem-rest-client: unsanitized application logging CVE-2017-2662 — foreman: Managing repositories with their id via hammer does not respect the role filters CVE-2018-1000119 — rack-protection: Timing attack in authenticity_token.rb CVE-2019-16782 — rubygem-rack: hijack sessions by using timing attacks targeting the session id CVE-2019-18874 — python-psutil: Double free because of refcount mishandling CVE-2020-8162 — rubygem-activestorage: circumvention of file size limits in ActiveStorage CVE-2020-8164 — rubygem-actionpack: possible strong parameters bypass CVE-2020-8165 — rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore CVE-2020-8166 — rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token CVE-2020-8167 — rubygem-actionview: CSRF vulnerability in rails-ujs CVE-2020-8185 — rubygem-rails: untrusted users able to run pending migrations in production CVE-2020-9402 — django: potential SQL injection via "tolerance" parameter in GIS functions and aggregates on Oracle CVE-2020-11612 — netty: compression/decompression codecs don't enforce limits on buffer allocation sizes CVE-2020-14335 — foreman: world-readable OMAPI secret through the ISC DHCP server CVE-2020-15169 — rubygem-activeview: Cross-site scripting in translation helpers CVE-2020-25633 — resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling

🎯 Affected products200

  • Red Hat Satellite 6.9
  • Red Hat Satellite Capsule 6.9
  • ansible-collection-redhat-satellite-0:2.0.1-1.el7sat.noarch as a component of Red Hat Satellite 6.9
  • ansible-collection-redhat-satellite-0:2.0.1-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.9
  • ansible-collection-redhat-satellite-0:2.0.1-1.el7sat.src as a component of Red Hat Satellite 6.9
  • ansible-collection-redhat-satellite-0:2.0.1-1.el7sat.src as a component of Red Hat Satellite Capsule 6.9
  • ansible-runner-0:1.4.6-1.el7ar.noarch as a component of Red Hat Satellite 6.9
  • ansible-runner-0:1.4.6-1.el7ar.noarch as a component of Red Hat Satellite Capsule 6.9
  • ansible-runner-0:1.4.6-1.el7ar.src as a component of Red Hat Satellite 6.9
  • ansible-runner-0:1.4.6-1.el7ar.src as a component of Red Hat Satellite Capsule 6.9
  • ansiblerole-foreman_scap_client-0:0.1.0-1.el7sat.noarch as a component of Red Hat Satellite 6.9
  • ansiblerole-foreman_scap_client-0:0.1.0-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.9
  • ansiblerole-foreman_scap_client-0:0.1.0-1.el7sat.src as a component of Red Hat Satellite 6.9
  • ansiblerole-foreman_scap_client-0:0.1.0-1.el7sat.src as a component of Red Hat Satellite Capsule 6.9
  • ansiblerole-insights-client-0:1.7.1-1.el7sat.noarch as a component of Red Hat Satellite 6.9
  • ansiblerole-insights-client-0:1.7.1-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.9
  • ansiblerole-insights-client-0:1.7.1-1.el7sat.src as a component of Red Hat Satellite 6.9
  • ansiblerole-insights-client-0:1.7.1-1.el7sat.src as a component of Red Hat Satellite Capsule 6.9
  • ansiblerole-satellite-receptor-installer-0:0.6.13-1.el7sat.noarch as a component of Red Hat Satellite 6.9
  • ansiblerole-satellite-receptor-installer-0:0.6.13-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.9
  • ansiblerole-satellite-receptor-installer-0:0.6.13-1.el7sat.src as a component of Red Hat Satellite 6.9
  • ansiblerole-satellite-receptor-installer-0:0.6.13-1.el7sat.src as a component of Red Hat Satellite Capsule 6.9
  • candlepin-0:3.1.26-1.el7sat.noarch as a component of Red Hat Satellite 6.9
  • candlepin-0:3.1.26-1.el7sat.src as a component of Red Hat Satellite 6.9
  • candlepin-selinux-0:3.1.26-1.el7sat.noarch as a component of Red Hat Satellite 6.9
  • crane-selinux-0:3.5.1-1.el7sat.noarch as a component of Red Hat Satellite 6.9
  • crane-selinux-0:3.5.1-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.9
  • createrepo_c-0:0.17.1-1.el7pc.src as a component of Red Hat Satellite 6.9
  • createrepo_c-0:0.17.1-1.el7pc.src as a component of Red Hat Satellite Capsule 6.9
  • createrepo_c-0:0.17.1-1.el7pc.x86_64 as a component of Red Hat Satellite 6.9
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The permissions on log files can be changed, e.g. using "chmod o-rwx" to prevent anyone but the user and group owner of the file from reading it. Additionally the group permissions can also be removed, e.g. "chmod g-rwx" if only the user owning the file should be able to see it. Workaround: There is no mitigation for this issue, the flaw can only be resolved by applying updates. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible. Workaround: There is no known mitigation for this issue, the flaw can only be resolved by applying updates. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (328)