-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenStack Platform 16.1.9 (python-XStatic-Angular) security update Advisory ID: RHSA-2022:8866-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:8866 Issue date: 2022-12-07 CVE Names: CVE-2019-10768 ==================================================================== 1. Summary: An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 16.1 - noarch 3. Description: Angular JavaScript library packaged for setuptools (easy_install) / pip. Security Fix(es): * Prototype pollution in merge function could result in code injection (CVE-2019-10768) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1813309 - CVE-2019-10768 AngularJS: Prototype pollution in merge function could result in code injection 6. Package List: Red Hat OpenStack Platform 16.1: Source: python-XStatic-Angular-1.5.8.0-13.el8ost.src.rpm noarch: XStatic-Angular-common-1.5.8.0-13.el8ost.noarch.rpm python3-XStatic-Angular-1.5.8.0-13.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-10768 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY5FpatzjgjWX9erEAQhl+w/5AfKkbI34bXXE7yfPixf+GvcfYai7s7Ku 3PBTymbKFdIla+c5zJfv5xux0YRYcqRt7tSlHHbybEEWxtrFXS9H8QSMW9q8h7QH B32AsI3ooAKyrTTZqWDXyri77Z2WeNGXbyTc/2OTbNJANNZjAE5OmP2YtrInh0I9 y0Dds9U1gWJMFqO6mKamISJz6V+k7bmaaFeSHwZ59LfwIW5HD8OXM7yLsxgWyb4d AxUSHugrRHgmjjoAwfylYlT+VPRgL9TvAa9/kuQgrGzq4Iy3bgtO3tkoJihweM/Y BjxthGzwXBBA6MKHiwCqujm0GwtkfaBKMGNNJOVeY5BkqEYJOOyjN6y9kE/cYZ1K zxvqotXYrhvx8RzQUNhaqpjreTa4AadLvGMdBEqMunAlXdUF9n3841lcfs0/daD3 I+N2YhPQHQ1ltusqp+50QIMf8EIAzptCQ4btMYhIRLdYYd7LwujcalqX5q4gC6is lngsTlZ/HwQai5UJ//BozTTWegW5zeBEcqFdqsS7D4WQM/bn5o1eR6shBIzxsAhA X3cpMk4vJ7E+nS+1wYVUEkmJZ26oZ4evCNYYpNu9FHtsUpN25IiM3qC5iw4GFIcZ /zLmVLXAt/YN/4zDuu5I9fQD/MkaMoGnYppPkMXxja2ducJNuPnZiO0n2Qi2XbwB qu4qTT4UppI=vX3U -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce