-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Satellite Tools 6.10.5 Async Bug Fix Update Advisory ID: RHSA-2022:4866-01 Product: Red Hat Satellite Tools Advisory URL: https://access.redhat.com/errata/RHSA-2022:4866 Issue date: 2022-06-01 CVE Names: CVE-2021-27023 CVE-2021-27025 ==================================================================== 1. Summary: Updated Satellite 6.10 Tools packages that fix several bugs are now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Satellite Tools 6.10 (v. 6.10.ELS Server) - i386, x86_64 Satellite Tools 6.10 (v. 7 Client) - x86_64 Satellite Tools 6.10 (v. 7 ComputeNode) - x86_64 Satellite Tools 6.10 (v. 7 Server) - ppc64le, x86_64 Satellite Tools 6.10 (v. 7 Workstation) - x86_64 Satellite Tools 6.10 (v. 7.2.AUS Server) - x86_64 Satellite Tools 6.10 (v. 7.3.AUS Server) - x86_64 Satellite Tools 6.10 (v. 7.4.AUS Server) - x86_64 Satellite Tools 6.10 (v. 7.4.E4S Server) - ppc64le, x86_64 Satellite Tools 6.10 (v. 7.4.TUS Server) - ppc64le, x86_64 Satellite Tools 6.10 (v. 7.6.AUS Server) - x86_64 Satellite Tools 6.10 (v. 7.6.E4S Server) - ppc64le, x86_64 Satellite Tools 6.10 (v. 7.6.TUS Server) - ppc64le, x86_64 Satellite Tools 6.10 (v. 7.7.AUS Server) - x86_64 Satellite Tools 6.10 (v. 7.7.E4S Server) - ppc64le, x86_64 Satellite Tools 6.10 (v. 7.7.TUS Server) - ppc64le, x86_64 Satellite Tools 6.10 (v. 8) - x86_64 Satellite Tools 6.10 (v. 8.1.E4S Server) - x86_64 Satellite Tools 6.10 (v. 8.1.EUS Server) - x86_64 Satellite Tools 6.10 (v. 8.2.AUS Server) - x86_64 Satellite Tools 6.10 (v. 8.2.EUS Server) - x86_64 Satellite Tools 6.10 (v. 8.2.TUS Server) - x86_64 Satellite Tools 6.10 (v. 8.4.AUS Server) - x86_64 Satellite Tools 6.10 (v. 8.4.E4S Server) - x86_64 Satellite Tools 6.10 (v. 8.4.EUS Server) - x86_64 Satellite Tools 6.10 (v. 8.4.TUS Server) - x86_64 Satellite Tools 6.10 (v. 8.6.AUS Server) - x86_64 Satellite Tools 6.10 (v. 8.6.E4S Server) - x86_64 Satellite Tools 6.10 (v. 8.6.EUS Server) - x86_64 Satellite Tools 6.10 (v. RHEL-ALT 7.6 Server) - aarch64, ppc64le Satellite Tools 6.10 for RHEL 8.2.E4S - x86_64 3. Description: Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Bugs Fixed: 2023853 CVE-2021-27025 puppet: silent configuration failure in agent 2023859 CVE-2021-27023 puppet: unsafe HTTP redirect 2027254 CVE-2021-27025 CVE-2021-27023 CVE-2021-27025 puppet: multiple flaws in Satellite Tools [rhn_satellite_6.10] Security Fix(es): * Puppet Agent: Unsafe HTTP redirect (CVE-2021-27023) * Puppet Agent: Silent configuration failure in agent (CVE-2021-27025) Users of Red Hat Satellite Tools on all Red Hat Enterprise Linux versions are advised to upgrade to these updated packages. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2023853 - CVE-2021-27025 puppet: silent configuration failure in agent 2023859 - CVE-2021-27023 puppet: unsafe HTTP redirect 6. Package List: Satellite Tools 6.10 (v. 6.10.ELS Server): Source: puppet-agent-6.26.0-1.el6sat.src.rpm i386: puppet-agent-6.26.0-1.el6sat.i686.rpm x86_64: puppet-agent-6.26.0-1.el6sat.x86_64.rpm Satellite Tools 6.10 (v. 7 Client): Source: puppet-agent-6.26.0-1.el7sat.src.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7 ComputeNode): Source: puppet-agent-6.26.0-1.el7sat.src.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7 Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm ppc64le: puppet-agent-6.26.0-1.el7sat.ppc64le.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.2.AUS Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.3.AUS Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.4.AUS Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.4.E4S Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm ppc64le: puppet-agent-6.26.0-1.el7sat.ppc64le.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.4.TUS Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm ppc64le: puppet-agent-6.26.0-1.el7sat.ppc64le.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. RHEL-ALT 7.6 Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm aarch64: puppet-agent-6.26.0-1.el7sat.aarch64.rpm ppc64le: puppet-agent-6.26.0-1.el7sat.ppc64le.rpm Satellite Tools 6.10 (v. 7.6.AUS Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.6.E4S Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm ppc64le: puppet-agent-6.26.0-1.el7sat.ppc64le.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.6.TUS Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm ppc64le: puppet-agent-6.26.0-1.el7sat.ppc64le.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.7.AUS Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.7.E4S Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm ppc64le: puppet-agent-6.26.0-1.el7sat.ppc64le.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7.7.TUS Server): Source: puppet-agent-6.26.0-1.el7sat.src.rpm ppc64le: puppet-agent-6.26.0-1.el7sat.ppc64le.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 7 Workstation): Source: puppet-agent-6.26.0-1.el7sat.src.rpm x86_64: puppet-agent-6.26.0-1.el7sat.x86_64.rpm Satellite Tools 6.10 (v. 8): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.1.E4S Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.1.EUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.2.AUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 for RHEL 8.2.E4S: Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.2.EUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.2.TUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.4.AUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.4.E4S Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.4.EUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.4.TUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.6.AUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.6.E4S Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm Satellite Tools 6.10 (v. 8.6.EUS Server): Source: puppet-agent-6.26.0-1.el8sat.src.rpm x86_64: puppet-agent-6.26.0-1.el8sat.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-27023 https://access.redhat.com/security/cve/CVE-2021-27025 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYpgdztzjgjWX9erEAQj1mQ/6AvXPO/MC5aPzvrgjD12PBkH31h8GMXBJ GBTq6FdKOTcOPPGpi8C9PtxkdyiLel5PZH73ryfDJros3uNd3saFuXBXyjFxPYue VwiovYUWXCUfJ566Z8NtYZMfsD9o6pcDB2p5XLubG6iiuMFwbBX9k2knyjDhobU0 0bmrX3cpQhzq/APwQXvKIpHdEb0wKa7no2uOa0MdzTgFAPZCCdagsr5i8IgokSm5 qqs75C3dVWUnrBkKcCo7QyC2mWDJFFnwsuLsnq0+7SkUaCz+VtJrNMAWZPw2+Ghc Jgw0nYdwWdG5pEhtGm7L58PfrXk/mpbBdFe4eSV8i9TvAdR8JgFt4DHGFO9Xu+o3 w3pYDcBpLckazBpLokdCdMYjUJJyi7kAJkfh5CEVZ0CG1Ttqa6shm1NjhEETLgNt tyZadAOfd5oLl8eEYBH27u4Ayq55txxeZr+SzBb1tVokFYl+rn/EluQ2cuTup+MF bSS7nnCv7KP+F+C1oXXegrx7ffCaKOOP5uAncLUkd+Wt08bBfbdpDWVWNL8zzPp5 hv0hF1b1zhA23QAuUxlLvRdFjIiC78n9yYjTs3hgqdO9ovYYOiv6xZLISgPBHnF2 dMz5I/7iIBLH40BeT5bLVIMVYpYRvRepZCIsdZBCYumdGt3Pf/j3Ll0JHAERs2wq x9RetKf/2Js=Oeya -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce