[RHSA-2020:3936] ipa security, bug fix, and enhancement update

Severity Moderate
Affected Packages 14
CVEs 10

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

The following packages have been upgraded to a later upstream version: ipa (4.6.8). (BZ#1819725)

Security Fix(es):

  • js-jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)

  • bootstrap: XSS in the data-target attribute (CVE-2016-10735)

  • bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)

  • bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip. (CVE-2018-14042)

  • bootstrap: XSS in the tooltip data-viewport attribute (CVE-2018-20676)

  • bootstrap: XSS in the affix configuration target property (CVE-2018-20677)

  • bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)

  • js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection (CVE-2019-11358)

  • jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)

  • ipa: No password length restriction leads to denial of service (CVE-2020-1722)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.9 Release Notes linked from the References section.

ID
RHSA-2020:3936
Severity
moderate
URL
https://access.redhat.com/errata/RHSA-2020:3936
Published
2020-09-29T00:00:00
(4 years ago)
Modified
2020-09-29T00:00:00
(4 years ago)
Rights
Copyright 2020 Red Hat, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/python2-ipaserver?distro=redhat-7 redhat python2-ipaserver < 4.6.8-5.el7 redhat-7
Affected pkg:rpm/redhat/python2-ipalib?distro=redhat-7 redhat python2-ipalib < 4.6.8-5.el7 redhat-7
Affected pkg:rpm/redhat/python2-ipaclient?distro=redhat-7 redhat python2-ipaclient < 4.6.8-5.el7 redhat-7
Affected pkg:rpm/redhat/ipa-server?arch=x86_64&distro=redhat-7 redhat ipa-server < 4.6.8-5.el7 redhat-7 x86_64
Affected pkg:rpm/redhat/ipa-server-trust-ad?arch=x86_64&distro=redhat-7 redhat ipa-server-trust-ad < 4.6.8-5.el7 redhat-7 x86_64
Affected pkg:rpm/redhat/ipa-server-dns?distro=redhat-7 redhat ipa-server-dns < 4.6.8-5.el7 redhat-7
Affected pkg:rpm/redhat/ipa-server-common?distro=redhat-7 redhat ipa-server-common < 4.6.8-5.el7 redhat-7
Affected pkg:rpm/redhat/ipa-python-compat?distro=redhat-7 redhat ipa-python-compat < 4.6.8-5.el7 redhat-7
Affected pkg:rpm/redhat/ipa-common?distro=redhat-7 redhat ipa-common < 4.6.8-5.el7 redhat-7
Affected pkg:rpm/redhat/ipa-client?arch=x86_64&distro=redhat-7 redhat ipa-client < 4.6.8-5.el7 redhat-7 x86_64
Affected pkg:rpm/redhat/ipa-client?arch=s390x&distro=redhat-7 redhat ipa-client < 4.6.8-5.el7 redhat-7 s390x
Affected pkg:rpm/redhat/ipa-client?arch=ppc64le&distro=redhat-7 redhat ipa-client < 4.6.8-5.el7 redhat-7 ppc64le
Affected pkg:rpm/redhat/ipa-client?arch=ppc64&distro=redhat-7 redhat ipa-client < 4.6.8-5.el7 redhat-7 ppc64
Affected pkg:rpm/redhat/ipa-client-common?distro=redhat-7 redhat ipa-client-common < 4.6.8-5.el7 redhat-7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...