Issued:
2022-06-01
Updated:
2022-06-01

RHSA-2022:4866 - Important: Satellite Tools 6.10.5 Async Bug Fix Update


Synopsis

Important: Satellite Tools 6.10.5 Async Bug Fix Update

Type/Severity

Security Advisory Important

Topic

Updated Satellite 6.10 Tools packages that fix several bugs are now available.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments.

Bugs Fixed: 2023853 CVE-2021-27025 puppet: silent configuration failure in agent 2023859 CVE-2021-27023 puppet: unsafe HTTP redirect 2027254 CVE-2021-27025 CVE-2021-27023 CVE-2021-27025 puppet: multiple flaws in Satellite Tools [rhn_satellite_6.10]

Security Fix(es):

  • Puppet Agent: Unsafe HTTP redirect (CVE-2021-27023)
  • Puppet Agent: Silent configuration failure in agent (CVE-2021-27025)

Users of Red Hat Satellite Tools on all Red Hat Enterprise Linux versions are advised to upgrade to these updated packages.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

ProductVersionArch
Red Hat Enterprise Linux for x86_648x86_64
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions8.8x86_64
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions8.6x86_64
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions8.4x86_64
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions8.2x86_64
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions8.1x86_64
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions7.7x86_64
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions7.6x86_64
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions7.4x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support8.8x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support8.6x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support8.4x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support8.2x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support8.1x86_64
Red Hat Enterprise Linux for Scientific Computing7x86_64
Red Hat Enterprise Linux for Power, little endian7ppc64le
Red Hat Enterprise Linux for Power 97ppc64le
Red Hat Enterprise Linux for ARM 647aarch64
Red Hat Enterprise Linux Workstation7x86_64
Red Hat Enterprise Linux Server7x86_64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions7.7ppc64le
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions7.6ppc64le
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions7.4ppc64le
Red Hat Enterprise Linux Server - TUS8.8x86_64
Red Hat Enterprise Linux Server - TUS8.4x86_64
Red Hat Enterprise Linux Server - TUS8.2x86_64
Red Hat Enterprise Linux Server - TUS7.7x86_64
Red Hat Enterprise Linux Server - TUS7.6x86_64
Red Hat Enterprise Linux Server - TUS7.4x86_64
Red Hat Enterprise Linux Server - Extended Life Cycle Support6x86_64
Red Hat Enterprise Linux Server - Extended Life Cycle Support6i386
Red Hat Enterprise Linux Server - AUS8.6x86_64
Red Hat Enterprise Linux Server - AUS8.4x86_64
Red Hat Enterprise Linux Server - AUS8.2x86_64
Red Hat Enterprise Linux Server - AUS7.7x86_64
Red Hat Enterprise Linux Server - AUS7.6x86_64
Red Hat Enterprise Linux Server - AUS7.4x86_64
Red Hat Enterprise Linux Server - AUS7.3x86_64
Red Hat Enterprise Linux Server - AUS7.2x86_64
Red Hat Enterprise Linux Desktop7x86_64

Updated Packages

  • puppet-agent-6.26.0-1.el7sat.ppc64le.rpm
  • puppet-agent-6.26.0-1.el6sat.i686.rpm
  • puppet-agent-6.26.0-1.el8sat.src.rpm
  • puppet-agent-6.26.0-1.el6sat.x86_64.rpm
  • puppet-agent-6.26.0-1.el7sat.aarch64.rpm
  • puppet-agent-6.26.0-1.el7sat.x86_64.rpm
  • puppet-agent-6.26.0-1.el6sat.src.rpm
  • puppet-agent-6.26.0-1.el8sat.x86_64.rpm
  • puppet-agent-6.26.0-1.el7sat.src.rpm

Fixes

CVEs

References


Additional information