[RHSA-2020:3936] ipa security, bug fix, and enhancement update
Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.
The following packages have been upgraded to a later upstream version: ipa (4.6.8). (BZ#1819725)
Security Fix(es):
js-jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)
bootstrap: XSS in the data-target attribute (CVE-2016-10735)
bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)
bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip. (CVE-2018-14042)
bootstrap: XSS in the tooltip data-viewport attribute (CVE-2018-20676)
bootstrap: XSS in the affix configuration target property (CVE-2018-20677)
bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)
js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection (CVE-2019-11358)
jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)
ipa: No password length restriction leads to denial of service (CVE-2020-1722)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.9 Release Notes linked from the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/python2-ipaserver?distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/python2-ipalib?distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/python2-ipaclient?distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-server?arch=x86_64&distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-server-trust-ad?arch=x86_64&distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-server-dns?distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-server-common?distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-python-compat?distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-common?distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-client?arch=x86_64&distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-client?arch=s390x&distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-client?arch=ppc64le&distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-client?arch=ppc64&distro=redhat-7 | < 4.6.8-5.el7 |
pkg:rpm/redhat/ipa-client-common?distro=redhat-7 | < 4.6.8-5.el7 |
- ID
- RHSA-2020:3936
- Severity
- moderate
- URL
- https://access.redhat.com/errata/RHSA-2020:3936
- Published
-
2020-09-29T00:00:00
(4 years ago) - Modified
-
2020-09-29T00:00:00
(4 years ago) - Rights
- Copyright 2020 Red Hat, Inc.
- Other Advisories
-
- ALAS-2020-1422
- ALAS2-2020-1519
- ALAS2-2023-1905
- ALPINE:CVE-2015-9251
- ALPINE:CVE-2019-11358
- ALPINE:CVE-2020-11022
- ALSA-2020:4670
- ALSA-2020:4847
- ASA-201906-2
- ASA-201910-4
- DSA-4434-1
- DSA-4460-1
- DSA-4693-1
- ELSA-2020-3936
- ELSA-2022-7343
- ELSA-2022-9177
- FEDORA-2019-040857fd75
- FEDORA-2019-1a3edd7e8a
- FEDORA-2019-2a0ce0c58c
- FEDORA-2019-41d6ffd6f0
- FEDORA-2019-5f1a2cc839
- FEDORA-2019-7eaf0bbe7c
- FEDORA-2019-84a50e34a9
- FEDORA-2019-a06dffab1c
- FEDORA-2019-eba8e44ee6
- FEDORA-2019-f563e66380
- FEDORA-2020-0b32a59b54
- FEDORA-2020-11be4b36d4
- FEDORA-2020-36d2db5f51
- FEDORA-2020-7dddce530c
- FEDORA-2020-8a15713da2
- FEDORA-2020-fbb94073a1
- FEDORA-2020-fe94df8c34
- FREEBSD:1FB13175-ED52-11EA-8B93-001B217B3468
- FREEBSD:3C5A4FE0-9EBB-11E9-9169-FCAA147E860E
- FREEBSD:416CA0F4-3FE0-11E9-BBDD-6805CA0B3D42
- FREEBSD:81FCC2F9-E15A-11E9-ABBF-800DD28B22BD
- FREEBSD:CD2DC126-CFE4-11EA-9172-4C72B94353B5
- FREEBSD:ED8D5535-CA78-11E9-980B-999FF59C22EA
- FREEBSD:FFC73E87-87F0-11E9-AD56-FCAA147E860E
- GLSA-202007-03
- MAVEN:GHSA-3MGP-FX93-9XV5
- MAVEN:GHSA-3WQF-4X89-9G79
- MAVEN:GHSA-4P24-VMCR-4GQJ
- MAVEN:GHSA-6C3J-C64M-QHGQ
- MAVEN:GHSA-7MVR-5X2G-WFC8
- MAVEN:GHSA-9V3M-8FP8-MJ99
- MAVEN:GHSA-GXR4-XJJ5-5PX2
- MAVEN:GHSA-PH58-4VRJ-W6HR
- MAVEN:GHSA-RMXG-73GG-4P98
- NPM:GHSA-3MGP-FX93-9XV5
- NPM:GHSA-3WQF-4X89-9G79
- NPM:GHSA-4P24-VMCR-4GQJ
- NPM:GHSA-6C3J-C64M-QHGQ
- NPM:GHSA-7MVR-5X2G-WFC8
- NPM:GHSA-9V3M-8FP8-MJ99
- NPM:GHSA-GXR4-XJJ5-5PX2
- NPM:GHSA-PH58-4VRJ-W6HR
- NPM:GHSA-RMXG-73GG-4P98
- openSUSE-SU-2019:1839-1
- openSUSE-SU-2019:1872-1
- openSUSE-SU-2020:0395-1
- openSUSE-SU-2020:1060-1
- openSUSE-SU-2020:1106-1
- openSUSE-SU-2020:1888-1
- RHSA-2020:4670
- RHSA-2020:4847
- RHSA-2021:4142
- RHSA-2022:7343
- RLSA-2020:4670
- RLSA-2020:4847
- RUBYSEC:BOOTSTRAP-2016-10735
- RUBYSEC:BOOTSTRAP-2018-14040
- RUBYSEC:BOOTSTRAP-2018-14042
- RUBYSEC:BOOTSTRAP-2018-20676
- RUBYSEC:BOOTSTRAP-2018-20677
- RUBYSEC:BOOTSTRAP-2019-8331
- RUBYSEC:BOOTSTRAP-SASS-2016-10735
- RUBYSEC:BOOTSTRAP-SASS-2018-14040
- RUBYSEC:BOOTSTRAP-SASS-2018-14042
- RUBYSEC:BOOTSTRAP-SASS-2018-20676
- RUBYSEC:BOOTSTRAP-SASS-2018-20677
- RUBYSEC:BOOTSTRAP-SASS-2019-8331
- RUBYSEC:JQUERY-RAILS-2015-9251
- RUBYSEC:JQUERY-RAILS-2019-11358
- RUBYSEC:JQUERY-RAILS-2020-11022
- RUBYSEC:TWITTER-BOOTSTRAP-RAILS-2019-8331
- SUSE-SU-2020:0737-1
- SUSE-SU-2020:2292-1
- SUSE-SU-2020:2373-1
- SUSE-SU-2020:2650-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/python2-ipaserver?distro=redhat-7 | redhat | python2-ipaserver | < 4.6.8-5.el7 | redhat-7 | ||
Affected | pkg:rpm/redhat/python2-ipalib?distro=redhat-7 | redhat | python2-ipalib | < 4.6.8-5.el7 | redhat-7 | ||
Affected | pkg:rpm/redhat/python2-ipaclient?distro=redhat-7 | redhat | python2-ipaclient | < 4.6.8-5.el7 | redhat-7 | ||
Affected | pkg:rpm/redhat/ipa-server?arch=x86_64&distro=redhat-7 | redhat | ipa-server | < 4.6.8-5.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/ipa-server-trust-ad?arch=x86_64&distro=redhat-7 | redhat | ipa-server-trust-ad | < 4.6.8-5.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/ipa-server-dns?distro=redhat-7 | redhat | ipa-server-dns | < 4.6.8-5.el7 | redhat-7 | ||
Affected | pkg:rpm/redhat/ipa-server-common?distro=redhat-7 | redhat | ipa-server-common | < 4.6.8-5.el7 | redhat-7 | ||
Affected | pkg:rpm/redhat/ipa-python-compat?distro=redhat-7 | redhat | ipa-python-compat | < 4.6.8-5.el7 | redhat-7 | ||
Affected | pkg:rpm/redhat/ipa-common?distro=redhat-7 | redhat | ipa-common | < 4.6.8-5.el7 | redhat-7 | ||
Affected | pkg:rpm/redhat/ipa-client?arch=x86_64&distro=redhat-7 | redhat | ipa-client | < 4.6.8-5.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/ipa-client?arch=s390x&distro=redhat-7 | redhat | ipa-client | < 4.6.8-5.el7 | redhat-7 | s390x | |
Affected | pkg:rpm/redhat/ipa-client?arch=ppc64le&distro=redhat-7 | redhat | ipa-client | < 4.6.8-5.el7 | redhat-7 | ppc64le | |
Affected | pkg:rpm/redhat/ipa-client?arch=ppc64&distro=redhat-7 | redhat | ipa-client | < 4.6.8-5.el7 | redhat-7 | ppc64 | |
Affected | pkg:rpm/redhat/ipa-client-common?distro=redhat-7 | redhat | ipa-client-common | < 4.6.8-5.el7 | redhat-7 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |