[ALSA-2020:4670] idm:DL1 and idm:client security, bug fix, and enhancement update
An update for the idm:DL1 and idm:client modules is now available for AlmaLinux AlmaLinux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
AlmaLinux Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.
The following packages have been upgraded to a later upstream version: ipa (4.8.7), softhsm (2.6.0), opendnssec (2.1.6). (BZ#1759888, BZ#1818765, BZ#1818877)
Security Fix(es):
js-jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)
bootstrap: XSS in the data-target attribute (CVE-2016-10735)
bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)
bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042)
bootstrap: XSS in the tooltip data-viewport attribute (CVE-2018-20676)
bootstrap: XSS in the affix configuration target property (CVE-2018-20677)
bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)
js-jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)
jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)
ipa: No password length restriction leads to denial of service (CVE-2020-1722)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
- ID
- ALSA-2020:4670
- Severity
- moderate
- URL
- https://errata.almalinux.org/ALSA-2020:4670.html
- Published
-
2020-11-03T12:25:36
(3 years ago) - Modified
-
2022-04-29T15:25:47
(2 years ago) - Rights
- Copyright 2022 AlmaLinux OS
- Other Advisories
-
- ALAS-2020-1422
- ALAS2-2020-1519
- ALAS2-2023-1905
- ALPINE:CVE-2015-9251
- ALPINE:CVE-2019-11358
- ALPINE:CVE-2020-11022
- ALSA-2020:4847
- ASA-201906-2
- ASA-201910-4
- DSA-4434-1
- DSA-4460-1
- DSA-4693-1
- ELSA-2020-3936
- ELSA-2022-7343
- ELSA-2022-9177
- FEDORA-2019-040857fd75
- FEDORA-2019-1a3edd7e8a
- FEDORA-2019-2a0ce0c58c
- FEDORA-2019-41d6ffd6f0
- FEDORA-2019-5f1a2cc839
- FEDORA-2019-7eaf0bbe7c
- FEDORA-2019-84a50e34a9
- FEDORA-2019-a06dffab1c
- FEDORA-2019-eba8e44ee6
- FEDORA-2019-f563e66380
- FEDORA-2020-0b32a59b54
- FEDORA-2020-11be4b36d4
- FEDORA-2020-36d2db5f51
- FEDORA-2020-7dddce530c
- FEDORA-2020-8a15713da2
- FEDORA-2020-fbb94073a1
- FEDORA-2020-fe94df8c34
- FREEBSD:1FB13175-ED52-11EA-8B93-001B217B3468
- FREEBSD:3C5A4FE0-9EBB-11E9-9169-FCAA147E860E
- FREEBSD:416CA0F4-3FE0-11E9-BBDD-6805CA0B3D42
- FREEBSD:81FCC2F9-E15A-11E9-ABBF-800DD28B22BD
- FREEBSD:CD2DC126-CFE4-11EA-9172-4C72B94353B5
- FREEBSD:ED8D5535-CA78-11E9-980B-999FF59C22EA
- FREEBSD:FFC73E87-87F0-11E9-AD56-FCAA147E860E
- GLSA-202007-03
- MAVEN:GHSA-3MGP-FX93-9XV5
- MAVEN:GHSA-3WQF-4X89-9G79
- MAVEN:GHSA-4P24-VMCR-4GQJ
- MAVEN:GHSA-6C3J-C64M-QHGQ
- MAVEN:GHSA-7MVR-5X2G-WFC8
- MAVEN:GHSA-9V3M-8FP8-MJ99
- MAVEN:GHSA-GXR4-XJJ5-5PX2
- MAVEN:GHSA-PH58-4VRJ-W6HR
- MAVEN:GHSA-RMXG-73GG-4P98
- NPM:GHSA-3MGP-FX93-9XV5
- NPM:GHSA-3WQF-4X89-9G79
- NPM:GHSA-4P24-VMCR-4GQJ
- NPM:GHSA-6C3J-C64M-QHGQ
- NPM:GHSA-7MVR-5X2G-WFC8
- NPM:GHSA-9V3M-8FP8-MJ99
- NPM:GHSA-GXR4-XJJ5-5PX2
- NPM:GHSA-PH58-4VRJ-W6HR
- NPM:GHSA-RMXG-73GG-4P98
- openSUSE-SU-2019:1839-1
- openSUSE-SU-2019:1872-1
- openSUSE-SU-2020:0395-1
- openSUSE-SU-2020:1060-1
- openSUSE-SU-2020:1106-1
- openSUSE-SU-2020:1888-1
- RHSA-2020:3936
- RHSA-2020:4670
- RHSA-2020:4847
- RHSA-2021:4142
- RHSA-2022:7343
- RLSA-2020:4670
- RLSA-2020:4847
- RUBYSEC:BOOTSTRAP-2016-10735
- RUBYSEC:BOOTSTRAP-2018-14040
- RUBYSEC:BOOTSTRAP-2018-14042
- RUBYSEC:BOOTSTRAP-2018-20676
- RUBYSEC:BOOTSTRAP-2018-20677
- RUBYSEC:BOOTSTRAP-2019-8331
- RUBYSEC:BOOTSTRAP-SASS-2016-10735
- RUBYSEC:BOOTSTRAP-SASS-2018-14040
- RUBYSEC:BOOTSTRAP-SASS-2018-14042
- RUBYSEC:BOOTSTRAP-SASS-2018-20676
- RUBYSEC:BOOTSTRAP-SASS-2018-20677
- RUBYSEC:BOOTSTRAP-SASS-2019-8331
- RUBYSEC:JQUERY-RAILS-2015-9251
- RUBYSEC:JQUERY-RAILS-2019-11358
- RUBYSEC:JQUERY-RAILS-2020-11022
- RUBYSEC:TWITTER-BOOTSTRAP-RAILS-2019-8331
- SUSE-SU-2020:0737-1
- SUSE-SU-2020:2292-1
- SUSE-SU-2020:2373-1
- SUSE-SU-2020:2650-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2015-9251 | https://vulners.com/cve/CVE-2015-9251 | |
CVE | CVE-2016-10735 | https://vulners.com/cve/CVE-2016-10735 | |
CVE | CVE-2018-14040 | https://vulners.com/cve/CVE-2018-14040 | |
CVE | CVE-2018-14042 | https://vulners.com/cve/CVE-2018-14042 | |
CVE | CVE-2018-20676 | https://vulners.com/cve/CVE-2018-20676 | |
CVE | CVE-2018-20677 | https://vulners.com/cve/CVE-2018-20677 | |
CVE | CVE-2019-11358 | https://vulners.com/cve/CVE-2019-11358 | |
CVE | CVE-2019-8331 | https://vulners.com/cve/CVE-2019-8331 | |
CVE | CVE-2020-11022 | https://vulners.com/cve/CVE-2020-11022 | |
CVE | CVE-2020-1722 | https://vulners.com/cve/CVE-2020-1722 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.6 | almalinux | python3-yubico | < 1.3.2-9.module_el8.6.0+2737+7e73ea90 | almalinux-8.6 | noarch | |
Affected | pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.5 | almalinux | python3-yubico | < 1.3.2-9.module_el8.5.0+2641+983b221b | almalinux-8.5 | noarch | |
Affected | pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.3 | almalinux | python3-yubico | < 1.3.2-9.module_el8.3.0+2036+6212645f | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.6 | almalinux | python3-qrcode | < 5.1-12.module_el8.6.0+2737+7e73ea90 | almalinux-8.6 | noarch | |
Affected | pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.5 | almalinux | python3-qrcode | < 5.1-12.module_el8.5.0+2641+983b221b | almalinux-8.5 | noarch | |
Affected | pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.3 | almalinux | python3-qrcode | < 5.1-12.module_el8.3.0+2036+6212645f | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.6 | almalinux | python3-qrcode-core | < 5.1-12.module_el8.6.0+2737+7e73ea90 | almalinux-8.6 | noarch | |
Affected | pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.5 | almalinux | python3-qrcode-core | < 5.1-12.module_el8.5.0+2641+983b221b | almalinux-8.5 | noarch | |
Affected | pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.3 | almalinux | python3-qrcode-core | < 5.1-12.module_el8.3.0+2036+6212645f | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.6 | almalinux | python3-pyusb | < 1.0.0-9.module_el8.6.0+2737+7e73ea90 | almalinux-8.6 | noarch | |
Affected | pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.5 | almalinux | python3-pyusb | < 1.0.0-9.module_el8.5.0+2641+983b221b | almalinux-8.5 | noarch | |
Affected | pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.3 | almalinux | python3-pyusb | < 1.0.0-9.module_el8.3.0+2036+6212645f | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/python3-kdcproxy?arch=noarch&distro=almalinux-8.6 | almalinux | python3-kdcproxy | < 0.4-5.module_el8.6.0+2881+2f24dc92 | almalinux-8.6 | noarch | |
Affected | pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.6 | almalinux | python3-jwcrypto | < 0.5.0-1.module_el8.6.0+2737+7e73ea90 | almalinux-8.6 | noarch | |
Affected | pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.5 | almalinux | python3-jwcrypto | < 0.5.0-1.module_el8.5.0+2641+983b221b | almalinux-8.5 | noarch | |
Affected | pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.3 | almalinux | python3-jwcrypto | < 0.5.0-1.module_el8.3.0+2036+6212645f | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/python3-ipalib?arch=noarch&distro=almalinux-8.3 | almalinux | python3-ipalib | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/python3-ipaclient?arch=noarch&distro=almalinux-8.3 | almalinux | python3-ipaclient | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/python3-custodia?arch=noarch&distro=almalinux-8.6 | almalinux | python3-custodia | < 0.6.0-3.module_el8.6.0+2881+2f24dc92 | almalinux-8.6 | noarch | |
Affected | pkg:rpm/almalinux/ipa-selinux?arch=noarch&distro=almalinux-8.3 | almalinux | ipa-selinux | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/ipa-python-compat?arch=noarch&distro=almalinux-8.3 | almalinux | ipa-python-compat | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/ipa-healthcheck-core?arch=noarch&distro=almalinux-8.3 | almalinux | ipa-healthcheck-core | < 0.4-6.module_el8.3.0+2036+6212645f | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/ipa-common?arch=noarch&distro=almalinux-8.3 | almalinux | ipa-common | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/ipa-client?arch=x86_64&distro=almalinux-8.3 | almalinux | ipa-client | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | x86_64 | |
Affected | pkg:rpm/almalinux/ipa-client-samba?arch=x86_64&distro=almalinux-8.3 | almalinux | ipa-client-samba | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | x86_64 | |
Affected | pkg:rpm/almalinux/ipa-client-epn?arch=x86_64&distro=almalinux-8.3 | almalinux | ipa-client-epn | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | x86_64 | |
Affected | pkg:rpm/almalinux/ipa-client-common?arch=noarch&distro=almalinux-8.3 | almalinux | ipa-client-common | < 4.8.7-12.module_el8.3.0+2036+6212645f.alma | almalinux-8.3 | noarch | |
Affected | pkg:rpm/almalinux/custodia?arch=noarch&distro=almalinux-8.6 | almalinux | custodia | < 0.6.0-3.module_el8.6.0+2881+2f24dc92 | almalinux-8.6 | noarch |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |