RHSA-2025:2399MediumCVSS 6.3
Red Hat Security Advisory: Satellite 6.16.3 Async Update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-35195 — requests: subsequent requests to the same host ignore cert verification CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method CVE-2024-56374 — django: potential denial-of-service vulnerability in IPv6 validation
🎯 Affected products114
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 9
- candlepin-0:4.4.21-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- candlepin-0:4.4.21-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
- candlepin-0:4.4.21-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- candlepin-0:4.4.21-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
- candlepin-selinux-0:4.4.21-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- candlepin-selinux-0:4.4.21-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-0:3.12.0.6-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-0:3.12.0.6-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-0:3.12.0.6-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-0:3.12.0.6-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-cli-0:3.12.0.6-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-cli-0:3.12.0.6-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-debug-0:3.12.0.6-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-debug-0:3.12.0.6-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-dynflow-sidekiq-0:3.12.0.6-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-dynflow-sidekiq-0:3.12.0.6-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-ec2-0:3.12.0.6-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-ec2-0:3.12.0.6-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-installer-1:3.12.0.4-2.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-installer-1:3.12.0.4-2.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-installer-1:3.12.0.4-2.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-installer-1:3.12.0.4-2.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-installer-katello-1:3.12.0.4-2.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-installer-katello-1:3.12.0.4-2.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-journald-0:3.12.0.6-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-journald-0:3.12.0.6-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- foreman-libvirt-0:3.12.0.6-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
- foreman-libvirt-0:3.12.0.6-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
- +84 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.16/html/updating_red_hat_satellite/index
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2025:2399
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.16/html/updating_red_hat_satellite/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2337996
- externalhttps://issues.redhat.com/browse/SAT-30027
- externalhttps://issues.redhat.com/browse/SAT-30099
- externalhttps://issues.redhat.com/browse/SAT-30256
- externalhttps://issues.redhat.com/browse/SAT-30283
- externalhttps://issues.redhat.com/browse/SAT-30293
- externalhttps://issues.redhat.com/browse/SAT-30294
- externalhttps://issues.redhat.com/browse/SAT-30918
- externalhttps://issues.redhat.com/browse/SAT-30934
- externalhttps://issues.redhat.com/browse/SAT-30936
- externalhttps://issues.redhat.com/browse/SAT-30937
- externalhttps://issues.redhat.com/browse/SAT-30938
- externalhttps://issues.redhat.com/browse/SAT-30939
- externalhttps://issues.redhat.com/browse/SAT-30940
- externalhttps://issues.redhat.com/browse/SAT-30941
- externalhttps://issues.redhat.com/browse/SAT-30942
- externalhttps://issues.redhat.com/browse/SAT-30954
- externalhttps://issues.redhat.com/browse/SAT-30955
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_2399.json