First published: Tue Mar 16 2021(Updated: )
Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.<br>Security Fix(es):<br><li> jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution (CVE-2020-11023)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> cannot issue certs with multiple IP addresses corresponding to different hosts (BZ#1846349)</li> <li> CA-less install does not set required permissions on KDC certificate (BZ#1863619)</li> <li> IdM Web UI shows users as disabled (BZ#1884819)</li> <li> Authentication and login times are over several seconds due to unindexed ipaExternalMember (BZ#1892793)</li> <li> improve IPA PKI susbsystem detection by other means than a directory presence, use pki-server subsystem-find (BZ#1895197)</li> <li> IPA WebUI inaccessible after upgrading to RHEL 8.3 - idoverride-memberof.js missing (BZ#1897253)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ipa | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-client | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-client-common | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-common | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-debuginfo | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-python-compat | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-server | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-server-common | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-server-dns | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-server-trust-ad | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/python2-ipaclient | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/python2-ipalib | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/python2-ipaserver | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-client | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-debuginfo | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-client | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
redhat/ipa-debuginfo | <4.6.8-5.el7_9.4 | 4.6.8-5.el7_9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.