[ALSA-2020:4670] idm:DL1 and idm:client security, bug fix, and enhancement update

Severity Moderate
Affected Packages 28
CVEs 10

An update for the idm:DL1 and idm:client modules is now available for AlmaLinux AlmaLinux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

AlmaLinux Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

The following packages have been upgraded to a later upstream version: ipa (4.8.7), softhsm (2.6.0), opendnssec (2.1.6). (BZ#1759888, BZ#1818765, BZ#1818877)

Security Fix(es):

  • js-jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)

  • bootstrap: XSS in the data-target attribute (CVE-2016-10735)

  • bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)

  • bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042)

  • bootstrap: XSS in the tooltip data-viewport attribute (CVE-2018-20676)

  • bootstrap: XSS in the affix configuration target property (CVE-2018-20677)

  • bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)

  • js-jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)

  • jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)

  • ipa: No password length restriction leads to denial of service (CVE-2020-1722)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Package Affected Version
pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.6 < 1.3.2-9.module_el8.6.0+2737+7e73ea90
pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.5 < 1.3.2-9.module_el8.5.0+2641+983b221b
pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.3 < 1.3.2-9.module_el8.3.0+2036+6212645f
pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.6 < 5.1-12.module_el8.6.0+2737+7e73ea90
pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.5 < 5.1-12.module_el8.5.0+2641+983b221b
pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.3 < 5.1-12.module_el8.3.0+2036+6212645f
pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.6 < 5.1-12.module_el8.6.0+2737+7e73ea90
pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.5 < 5.1-12.module_el8.5.0+2641+983b221b
pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.3 < 5.1-12.module_el8.3.0+2036+6212645f
pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.6 < 1.0.0-9.module_el8.6.0+2737+7e73ea90
pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.5 < 1.0.0-9.module_el8.5.0+2641+983b221b
pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.3 < 1.0.0-9.module_el8.3.0+2036+6212645f
pkg:rpm/almalinux/python3-kdcproxy?arch=noarch&distro=almalinux-8.6 < 0.4-5.module_el8.6.0+2881+2f24dc92
pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.6 < 0.5.0-1.module_el8.6.0+2737+7e73ea90
pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.5 < 0.5.0-1.module_el8.5.0+2641+983b221b
pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.3 < 0.5.0-1.module_el8.3.0+2036+6212645f
pkg:rpm/almalinux/python3-ipalib?arch=noarch&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/python3-ipaclient?arch=noarch&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/python3-custodia?arch=noarch&distro=almalinux-8.6 < 0.6.0-3.module_el8.6.0+2881+2f24dc92
pkg:rpm/almalinux/ipa-selinux?arch=noarch&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/ipa-python-compat?arch=noarch&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/ipa-healthcheck-core?arch=noarch&distro=almalinux-8.3 < 0.4-6.module_el8.3.0+2036+6212645f
pkg:rpm/almalinux/ipa-common?arch=noarch&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/ipa-client?arch=x86_64&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/ipa-client-samba?arch=x86_64&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/ipa-client-epn?arch=x86_64&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/ipa-client-common?arch=noarch&distro=almalinux-8.3 < 4.8.7-12.module_el8.3.0+2036+6212645f.alma
pkg:rpm/almalinux/custodia?arch=noarch&distro=almalinux-8.6 < 0.6.0-3.module_el8.6.0+2881+2f24dc92
ID
ALSA-2020:4670
Severity
moderate
URL
https://errata.almalinux.org/ALSA-2020:4670.html
Published
2020-11-03T12:25:36
(3 years ago)
Modified
2022-04-29T15:25:47
(2 years ago)
Rights
Copyright 2022 AlmaLinux OS
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.6 almalinux python3-yubico < 1.3.2-9.module_el8.6.0+2737+7e73ea90 almalinux-8.6 noarch
Affected pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.5 almalinux python3-yubico < 1.3.2-9.module_el8.5.0+2641+983b221b almalinux-8.5 noarch
Affected pkg:rpm/almalinux/python3-yubico?arch=noarch&distro=almalinux-8.3 almalinux python3-yubico < 1.3.2-9.module_el8.3.0+2036+6212645f almalinux-8.3 noarch
Affected pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.6 almalinux python3-qrcode < 5.1-12.module_el8.6.0+2737+7e73ea90 almalinux-8.6 noarch
Affected pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.5 almalinux python3-qrcode < 5.1-12.module_el8.5.0+2641+983b221b almalinux-8.5 noarch
Affected pkg:rpm/almalinux/python3-qrcode?arch=noarch&distro=almalinux-8.3 almalinux python3-qrcode < 5.1-12.module_el8.3.0+2036+6212645f almalinux-8.3 noarch
Affected pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.6 almalinux python3-qrcode-core < 5.1-12.module_el8.6.0+2737+7e73ea90 almalinux-8.6 noarch
Affected pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.5 almalinux python3-qrcode-core < 5.1-12.module_el8.5.0+2641+983b221b almalinux-8.5 noarch
Affected pkg:rpm/almalinux/python3-qrcode-core?arch=noarch&distro=almalinux-8.3 almalinux python3-qrcode-core < 5.1-12.module_el8.3.0+2036+6212645f almalinux-8.3 noarch
Affected pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.6 almalinux python3-pyusb < 1.0.0-9.module_el8.6.0+2737+7e73ea90 almalinux-8.6 noarch
Affected pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.5 almalinux python3-pyusb < 1.0.0-9.module_el8.5.0+2641+983b221b almalinux-8.5 noarch
Affected pkg:rpm/almalinux/python3-pyusb?arch=noarch&distro=almalinux-8.3 almalinux python3-pyusb < 1.0.0-9.module_el8.3.0+2036+6212645f almalinux-8.3 noarch
Affected pkg:rpm/almalinux/python3-kdcproxy?arch=noarch&distro=almalinux-8.6 almalinux python3-kdcproxy < 0.4-5.module_el8.6.0+2881+2f24dc92 almalinux-8.6 noarch
Affected pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.6 almalinux python3-jwcrypto < 0.5.0-1.module_el8.6.0+2737+7e73ea90 almalinux-8.6 noarch
Affected pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.5 almalinux python3-jwcrypto < 0.5.0-1.module_el8.5.0+2641+983b221b almalinux-8.5 noarch
Affected pkg:rpm/almalinux/python3-jwcrypto?arch=noarch&distro=almalinux-8.3 almalinux python3-jwcrypto < 0.5.0-1.module_el8.3.0+2036+6212645f almalinux-8.3 noarch
Affected pkg:rpm/almalinux/python3-ipalib?arch=noarch&distro=almalinux-8.3 almalinux python3-ipalib < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 noarch
Affected pkg:rpm/almalinux/python3-ipaclient?arch=noarch&distro=almalinux-8.3 almalinux python3-ipaclient < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 noarch
Affected pkg:rpm/almalinux/python3-custodia?arch=noarch&distro=almalinux-8.6 almalinux python3-custodia < 0.6.0-3.module_el8.6.0+2881+2f24dc92 almalinux-8.6 noarch
Affected pkg:rpm/almalinux/ipa-selinux?arch=noarch&distro=almalinux-8.3 almalinux ipa-selinux < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 noarch
Affected pkg:rpm/almalinux/ipa-python-compat?arch=noarch&distro=almalinux-8.3 almalinux ipa-python-compat < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 noarch
Affected pkg:rpm/almalinux/ipa-healthcheck-core?arch=noarch&distro=almalinux-8.3 almalinux ipa-healthcheck-core < 0.4-6.module_el8.3.0+2036+6212645f almalinux-8.3 noarch
Affected pkg:rpm/almalinux/ipa-common?arch=noarch&distro=almalinux-8.3 almalinux ipa-common < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 noarch
Affected pkg:rpm/almalinux/ipa-client?arch=x86_64&distro=almalinux-8.3 almalinux ipa-client < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 x86_64
Affected pkg:rpm/almalinux/ipa-client-samba?arch=x86_64&distro=almalinux-8.3 almalinux ipa-client-samba < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 x86_64
Affected pkg:rpm/almalinux/ipa-client-epn?arch=x86_64&distro=almalinux-8.3 almalinux ipa-client-epn < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 x86_64
Affected pkg:rpm/almalinux/ipa-client-common?arch=noarch&distro=almalinux-8.3 almalinux ipa-client-common < 4.8.7-12.module_el8.3.0+2036+6212645f.alma almalinux-8.3 noarch
Affected pkg:rpm/almalinux/custodia?arch=noarch&distro=almalinux-8.6 almalinux custodia < 0.6.0-3.module_el8.6.0+2881+2f24dc92 almalinux-8.6 noarch
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...