RHSA-2025:4576HighCVSS 8.5

Red Hat Security Advisory: Satellite 6.17.0 release

Published
May 6, 2025
Last Modified
September 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method CVE-2024-56374 — django: potential denial-of-service vulnerability in IPv6 validation CVE-2025-27407 — graphql-ruby: Remote code execution when loading a crafted GraphQL schema CVE-2025-27610 — rack: rubygem-rack: Local File Inclusion in Rack::Static

🎯 Affected products200

  • Red Hat Satellite 6.17 for RHEL 9
  • ansible-collection-redhat-satellite-0:5.1.0-2.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-collection-redhat-satellite-0:5.1.0-2.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-collection-redhat-satellite_operations-0:3.0.0-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-collection-redhat-satellite_operations-0:3.0.0-1.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-core-1:2.16.14-3.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-core-1:2.16.14-3.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-lint-0:5.4.0-1.el9pc.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-lint-0:5.4.0-1.el9pc.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-runner-0:2.3.6-2.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-runner-0:2.3.6-2.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansible-test-1:2.16.14-3.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansiblerole-foreman_scap_client-0:0.3.0-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansiblerole-foreman_scap_client-0:0.3.0-1.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansiblerole-insights-client-0:1.7.1-2.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • ansiblerole-insights-client-0:1.7.1-2.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • candlepin-0:4.4.21-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • candlepin-0:4.4.21-1.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • candlepin-selinux-0:4.4.21-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
  • cjson-0:1.7.17-1.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • cjson-0:1.7.17-1.el9sat.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
  • cjson-debuginfo-0:1.7.17-1.el9sat.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
  • cjson-debugsource-0:1.7.17-1.el9sat.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
  • createrepo_c-0:1.1.3-1.el9pc.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • createrepo_c-0:1.1.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
  • createrepo_c-debuginfo-0:1.1.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
  • createrepo_c-debugsource-0:1.1.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
  • createrepo_c-libs-0:1.1.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
  • createrepo_c-libs-debuginfo-0:1.1.3-1.el9pc.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
  • dynflow-utils-0:1.6.3-1.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.17/html/updating_red_hat_satellite/index Workaround: A successful exploitation of this flaw requires GraphQL schema loading. Limiting the schema loading to trusted or authenticated users will limit the impact of the vulnerability. Coupling that with a strict input validation for all GraphQL schema being loaded would reduce the risk of a successful attack and cover as a possible mitigation strategy for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (231)