RHSA-2021:1846MediumCVSS 6.1
Red Hat Security Advisory: idm:DL1 and idm:client security, bug fix, and enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods
🎯 Affected products167
- Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.6-2.module+el8.4.0+9328+4ec4e316.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.6-2.module+el8.4.0+9328+4ec4e316.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.6-2.module+el8.4.0+9328+4ec4e316.s390x (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.6-2.module+el8.4.0+9328+4ec4e316.src (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-0:11.6-2.module+el8.4.0+9328+4ec4e316.x86_64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debuginfo-0:11.6-2.module+el8.4.0+9328+4ec4e316.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debuginfo-0:11.6-2.module+el8.4.0+9328+4ec4e316.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debuginfo-0:11.6-2.module+el8.4.0+9328+4ec4e316.s390x (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debuginfo-0:11.6-2.module+el8.4.0+9328+4ec4e316.x86_64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debugsource-0:11.6-2.module+el8.4.0+9328+4ec4e316.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debugsource-0:11.6-2.module+el8.4.0+9328+4ec4e316.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debugsource-0:11.6-2.module+el8.4.0+9328+4ec4e316.s390x (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-dyndb-ldap-debugsource-0:11.6-2.module+el8.4.0+9328+4ec4e316.x86_64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- custodia-0:0.6.0-3.module+el8.1.0+4098+f286395e.noarch (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- custodia-0:0.6.0-3.module+el8.1.0+4098+f286395e.src (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-0:4.9.2-3.module+el8.4.0+10412+5ecb5b37.src (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-0:4.9.2-3.module+el8.4.0+10413+a92f1bfa.src (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.9.2-3.module+el8.4.0+10412+5ecb5b37.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.9.2-3.module+el8.4.0+10412+5ecb5b37.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.9.2-3.module+el8.4.0+10412+5ecb5b37.s390x (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.9.2-3.module+el8.4.0+10412+5ecb5b37.x86_64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.9.2-3.module+el8.4.0+10413+a92f1bfa.aarch64 (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.9.2-3.module+el8.4.0+10413+a92f1bfa.ppc64le (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.9.2-3.module+el8.4.0+10413+a92f1bfa.s390x (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-0:4.9.2-3.module+el8.4.0+10413+a92f1bfa.x86_64 (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-common-0:4.9.2-3.module+el8.4.0+10412+5ecb5b37.noarch (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-common-0:4.9.2-3.module+el8.4.0+10413+a92f1bfa.noarch (idm:client) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-debuginfo-0:4.9.2-3.module+el8.4.0+10412+5ecb5b37.aarch64 (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- ipa-client-debuginfo-0:4.9.2-3.module+el8.4.0+10412+5ecb5b37.ppc64le (idm:DL1) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +137 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (56)
- selfhttps://access.redhat.com/errata/RHSA-2021:1846
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=871208
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1340463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1357495
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1484088
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1542737
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1544379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1660877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1779981
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1780328
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1780510
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1780782
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1784657
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1809215
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1810148
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812871
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1824193
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1850004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1851835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857272
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1860129
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1866558
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1872603
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1875001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1882340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891056
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891505
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891735
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891741
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891832
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891850
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1894800
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1901068
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1902173
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1902727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1903025
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1904484
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1904612
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1905919
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1909876
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1912845
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1922955
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1923900
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1924026
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1924501
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1924812
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1925410
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1926699
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1926910
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1928900
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1930426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1932289
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1939371
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1846.json