Red Hat Security Advisory: Satellite 6.17.12 Async Update
🔗 CVE IDs covered (24)
📋 Description
CVE-2026-12405 — rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter CVE-2026-12423 — foreman: unauthenticated information disclosure via provisioning token validation flaw CVE-2026-12540 — foreman: command injection in foreman-rake errors:fetch_log via request_id parameter CVE-2026-12541 — foreman: command injection in foreman-rake database tasks CVE-2026-12542 — foreman: command injection in foreman-tail CVE-2026-12544 — foreman: SSTI and insecure deserialization in foreman-rake configuration CVE-2026-12545 — rubygem-hammer_cli: command injection via insecure editor invocation CVE-2026-33154 — dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-56097 — rubygem-katello: SQL injection in Registry Proxy via labels CVE-2026-56098 — rubygem-katello: improper authorization logic allows resource enumeration CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-79654 — ketello: Katello Content View History API Cross-Organization Authorization Bypass CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation CVE-2026-96658 — foreman: Safemode Bypass leading to RCE CVE-2026-96659 — foreman: Excessive Permissions for Viewer Role on Preview
🎯 Affected products44
- Red Hat Satellite 6.17 for RHEL 9
- foreman-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-0:3.14.0.22-1.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-cli-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-debug-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-dynflow-sidekiq-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-ec2-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-journald-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-libvirt-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-openstack-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-ovirt-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-pcp-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-postgresql-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-redis-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-service-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-telemetry-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- foreman-vmware-0:3.14.0.22-1.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- python-dynaconf-0:3.2.13-1.el9pc.src as a component of Red Hat Satellite 6.17 for RHEL 9
- python-gitpython-0:3.1.62-1.el9pc.src as a component of Red Hat Satellite 6.17 for RHEL 9
- python-lxml-0:5.3.1-2.el9pc.src as a component of Red Hat Satellite 6.17 for RHEL 9
- python-lxml-debugsource-0:5.3.1-2.el9pc.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
- python-sqlparse-0:0.6.0-1.el9pc.src as a component of Red Hat Satellite 6.17 for RHEL 9
- python3.11-dynaconf-0:3.2.13-1.el9pc.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- python3.11-gitpython-0:3.1.62-1.el9pc.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- python3.11-lxml-0:5.3.1-2.el9pc.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
- python3.11-lxml-debuginfo-0:5.3.1-2.el9pc.x86_64 as a component of Red Hat Satellite 6.17 for RHEL 9
- python3.11-sqlparse-0:0.6.0-1.el9pc.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- rubygem-foreman_remote_execution-0:15.0.2-2.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- rubygem-foreman_remote_execution-0:15.0.2-2.el9sat.src as a component of Red Hat Satellite 6.17 for RHEL 9
- rubygem-foreman_remote_execution-cockpit-0:15.0.2-2.el9sat.noarch as a component of Red Hat Satellite 6.17 for RHEL 9
- +14 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
🔗 References (29)
- selfhttps://access.redhat.com/errata/RHSA-2026:74505
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2449774
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488956
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489969
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489971
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489992
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489993
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2490542
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2490543
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515815
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515838
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515839
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2517518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2517523
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2517527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2520368
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2523205
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2523348
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2530744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2534185
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2536844
- externalhttps://issues.redhat.com/browse/SAT-50544
- externalhttps://issues.redhat.com/browse/SAT-50545
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74505.json