RHSA-2014:1186: Important: katello-configure security update
The katello-configure package provides the katello-configure script, whichconfigures the Katello installation, and the katello-upgrade script, whichhandles upgrades between versions.It was discovered that the default configuration of Elasticsearch enableddynamic scripting, allowing a remote attacker to execute arbitrary MVELexpressions and Java code via the source parameter passed to search.(CVE-2014-3120)All Subscription Asset Manager users are advised to upgrade to this updatedpackage. The update provides a script that modifies the elasticsearch.ymlconfiguration file to disable dynamic scripting. After updating, run the"katello-configure" command. This will update the elasticsearch.ymlconfiguration file and restart the elasticsearch service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:1186?
The severity of RHSA-2014:1186 is classified as important.
How do I fix RHSA-2014:1186?
To fix RHSA-2014:1186, update the katello-configure package to version 1.4.5.1-3.el6 or later.
What does RHSA-2014:1186 address?
RHSA-2014:1186 addresses a vulnerability in the default configuration of Elasticsearch within the katello-configure package.
Which package is affected by RHSA-2014:1186?
The affected package by RHSA-2014:1186 is katello-configure.
What is the recommended action for RHSA-2014:1186?
The recommended action for RHSA-2014:1186 is to ensure that the katello-configure package is updated to the latest secure version.