RHSA-2024:2010HighCVSS 7.6

Red Hat Security Advisory: Satellite 6.15.0 release

Published
April 23, 2024
Last Modified
August 6, 2026

🔗 CVE IDs covered (18)

📋 Description

CVE-2022-40896 — pygments: ReDoS in pygments CVE-2023-4320 — satellite: arithmetic overflow in satellite CVE-2023-5189 — Hub: insecure galaxy-importer tarfile extraction CVE-2023-36479 — jetty: Improper addition of quotation marks to user inputs in CgiServlet CVE-2023-37276 — python-aiohttp: HTTP request smuggling via llhttp HTTP request parser CVE-2023-38037 — rubygem-activesupport: File Disclosure of Locally Encrypted Files CVE-2023-40167 — jetty: Improper validation of HTTP/1 content-length CVE-2023-41164 — python-django: Potential denial of service vulnerability in django.utils.encoding.uri_to_iri() CVE-2023-43665 — python-django: Denial-of-service possibility in django.utils.text.Truncator CVE-2023-47627 — python-aiohttp: numerous issues in HTTP parser with header parsing CVE-2023-49081 — aiohttp: HTTP request modification CVE-2023-49082 — aiohttp: CRLF injection if user controls the HTTP method using aiohttp client CVE-2023-52323 — pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex CVE-2024-21647 — rubygem-puma: HTTP request smuggling when parsing chunked Transfer-Encoding Bodies CVE-2024-22047 — audited: race condition can lead to audit logs being incorrectly attributed to the wrong user CVE-2024-22195 — jinja2: HTML attribute injection when passing user input as keys to xmlattr filter CVE-2024-23334 — aiohttp: follow_symlinks directory traversal vulnerability CVE-2024-23829 — python-aiohttp: http request smuggling

🎯 Affected products200

  • Red Hat Satellite 6.15 for RHEL 8
  • ansible-collection-redhat-satellite-0:4.0.0-2.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansible-collection-redhat-satellite-0:4.0.0-2.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansible-collection-redhat-satellite_operations-0:2.1.0-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansible-collection-redhat-satellite_operations-0:2.1.0-1.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansible-lint-0:5.4.0-1.el8pc.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansible-lint-0:5.4.0-1.el8pc.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansible-runner-0:2.2.1-5.1.el8pc.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansible-runner-0:2.2.1-5.1.el8pc.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansiblerole-foreman_scap_client-0:0.2.0-2.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansiblerole-foreman_scap_client-0:0.2.0-2.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansiblerole-insights-client-0:1.7.1-2.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • ansiblerole-insights-client-0:1.7.1-2.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • candlepin-0:4.3.12-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • candlepin-0:4.3.12-1.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • candlepin-selinux-0:4.3.12-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • cjson-0:1.7.14-5.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • cjson-0:1.7.14-5.el8sat.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • cjson-debuginfo-0:1.7.14-5.el8sat.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • cjson-debugsource-0:1.7.14-5.el8sat.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • createrepo_c-0:1.0.2-5.el8pc.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • createrepo_c-0:1.0.2-5.el8pc.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • createrepo_c-debuginfo-0:1.0.2-5.el8pc.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • createrepo_c-debugsource-0:1.0.2-5.el8pc.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • createrepo_c-libs-0:1.0.2-5.el8pc.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • createrepo_c-libs-debuginfo-0:1.0.2-5.el8pc.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • dynflow-utils-0:1.6.3-1.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • dynflow-utils-0:1.6.3-1.el8sat.x86_64 as a component of Red Hat Satellite 6.15 for RHEL 8
  • foreman-0:3.9.1.6-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • foreman-0:3.9.1.6-1.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • +170 more not shown

✅ Remediation

For details on how to apply this update, refer to: * For upgrading connected Satellite: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html-single/upgrading_connected_red_hat_satellite_to_6.15 * For upgrading disconnected Satellite: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html-single/upgrading_disconnected_red_hat_satellite_to_6.15 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To work around this issue, users can set their umask to be more restrictive: $ umask 0077 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: If using follow_symlinks=True outside of a restricted local development environment, disable the option immediately. This option is NOT needed to follow symlinks that point to a location within the static root directory; it is only intended to allow a symlink to break out of the static directory. Even with this CVE fixed, there is still a substantial risk of misconfiguration when using this option on a server that accepts requests from remote users. Additionally, aiohttp has always recommended using a reverse proxy server (such as nginx) to handle static resources and not to use these static resources in aiohttp for production environments. Doing so also protects against this vulnerability, and is why we expect the number of affected users to be very low.

🔗 References (257)