RHSA-2024:11574MediumCVSS 5.9

Red Hat Security Advisory: Satellite 6.16.1 Async Update

Published
December 19, 2024
Last Modified
August 15, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-52304 — aiohttp: aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions

🎯 Affected products80

  • Red Hat Satellite 6.16 for RHEL 8
  • Red Hat Satellite 6.16 for RHEL 9
  • candlepin-0:4.4.20-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • candlepin-0:4.4.20-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • candlepin-0:4.4.20-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • candlepin-0:4.4.20-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • candlepin-selinux-0:4.4.20-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • candlepin-selinux-0:4.4.20-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • foreman-installer-1:3.12.0.3-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • foreman-installer-1:3.12.0.3-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • foreman-installer-1:3.12.0.3-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • foreman-installer-1:3.12.0.3-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • foreman-installer-katello-1:3.12.0.3-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • foreman-installer-katello-1:3.12.0.3-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • python-aiohappyeyeballs-0:2.4.3-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • python-aiohappyeyeballs-0:2.4.3-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • python-aiohttp-0:3.10.11-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • python-aiohttp-0:3.10.11-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • python-aiohttp-debugsource-0:3.10.11-1.el8pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 8
  • python-aiohttp-debugsource-0:3.10.11-1.el9pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 9
  • python-psycopg-0:3.2.3-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • python-psycopg-0:3.2.3-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • python-psycopg_c-0:3.2.3-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • python-psycopg_c-0:3.2.3-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • python-psycopg_c-debugsource-0:3.2.3-1.el8pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 8
  • python-psycopg_c-debugsource-0:3.2.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.16 for RHEL 9
  • python-pulpcore-0:3.49.28-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • python-pulpcore-0:3.49.28-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • python-yarl-0:1.13.1-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • python-yarl-0:1.13.1-1.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • +50 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.16/html/updating_red_hat_satellite/index

🔗 References (21)