RHSA-2025:3491HighCVSS 8.5

Red Hat Security Advisory: Satellite 6.15.5.2 Async Update

Published
April 1, 2025
Last Modified
August 15, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-56201 — jinja2: Jinja has a sandbox breakout through malicious filenames CVE-2025-27407 — graphql-ruby: Remote code execution when loading a crafted GraphQL schema CVE-2025-27610 — rack: rubygem-rack: Local File Inclusion in Rack::Static

🎯 Affected products16

  • Red Hat Satellite 6.15 for RHEL 8
  • python-jinja2-0:3.1.5-1.el8pc.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • python-pulpcore-0:3.39.25-1.el8pc.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • python3.11-jinja2-0:3.1.5-1.el8pc.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • python3.11-pulpcore-0:3.39.25-1.el8pc.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • rubygem-foreman_rh_cloud-0:9.0.60-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • rubygem-foreman_rh_cloud-0:9.0.60-1.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • rubygem-graphql-0:1.13.24-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • rubygem-graphql-0:1.13.24-1.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • rubygem-rack-0:2.2.13-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • rubygem-rack-0:2.2.13-1.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • satellite-0:6.15.5.2-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • satellite-0:6.15.5.2-1.el8sat.src as a component of Red Hat Satellite 6.15 for RHEL 8
  • satellite-capsule-0:6.15.5.2-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • satellite-cli-0:6.15.5.2-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8
  • satellite-common-0:6.15.5.2-1.el8sat.noarch as a component of Red Hat Satellite 6.15 for RHEL 8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index Workaround: To mitigate this vulnerabilty restrict user-controlled template filenames, ensuring they follow a predefined templates. Workaround: A successful exploitation of this flaw requires GraphQL schema loading. Limiting the schema loading to trusted or authenticated users will limit the impact of the vulnerability. Coupling that with a strict input validation for all GraphQL schema being loaded would reduce the risk of a successful attack and cover as a possible mitigation strategy for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (7)