Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Satellite
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Satellite
ID: RHSA-2025:2399
Distribution: Red Hat
Plattformen: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9
Datum: Mi, 5. März 2025, 23:25
Referenzen: https://issues.redhat.com/browse/SAT-30934
https://access.redhat.com/security/cve/CVE-2024-56326
https://issues.redhat.com/browse/SAT-30938
https://access.redhat.com/security/cve/CVE-2024-56374
https://issues.redhat.com/browse/SAT-30099
https://issues.redhat.com/browse/SAT-30283
https://issues.redhat.com/browse/SAT-30937
https://issues.redhat.com/browse/SAT-30940
https://issues.redhat.com/browse/SAT-30942
https://issues.redhat.com/browse/SAT-30954
https://issues.redhat.com/browse/SAT-30027
https://access.redhat.com/documentation/en-us/red_hat_satellite/6.16/html/updating_red_hat_satellite/index
https://issues.redhat.com/browse/SAT-30293
https://bugzilla.redhat.com/show_bug.cgi?id=2333856
https://issues.redhat.com/browse/SAT-30955
https://issues.redhat.com/browse/SAT-30294
https://access.redhat.com/errata/RHSA-2025:2399
https://issues.redhat.com/browse/SAT-30256
https://issues.redhat.com/browse/SAT-30939
https://issues.redhat.com/browse/SAT-30918
https://bugzilla.redhat.com/show_bug.cgi?id=2337996
https://issues.redhat.com/browse/SAT-30936
https://issues.redhat.com/browse/SAT-30941
Applikationen: Satellite

Originalnachricht

A new release is now available for Red Hat Satellite 6.16 for RHEL 8 and 9.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

Red Hat Satellite is a system management solution that allows organizations
to configure and maintain their systems without the necessity to provide
public Internet access to their servers or other client systems. It
performs provisioning and configuration management of predefined standard
operating environments.

Security Fix(es):

* python-jinja2: Jinja has a sandbox breakout through indirect reference to
format method (CVE-2024-56326)

* python-django: potential denial-of-service vulnerability in IPv6 validation
(CVE-2024-56374)

Users of Red Hat Satellite are advised to upgrade to these updated
packages, which fix these bugs.

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2024-56326: Protection Mechanism Failure (CWE-693)
CVE-2024-56374: Allocation of Resources Without Limits or Throttling (CWE-770)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung