RHSA-2024:10806: Moderate: Satellite 6.15.5 Async Update
Moderate: Satellite 6.15.5 Async Update
Other sources
Red Hat Satellite is a system management solution that allows organizations<br>to configure and maintain their systems without the necessity to provide<br>public Internet access to their servers or other client systems. It<br>performs provisioning and configuration management of predefined standard<br>operating environments.<br>Security Fix(es):<br><li> rubygem-activestorage: Possible Sensitive Session Information Leak in Active Storage (CVE-2024-26144)</li> <li> rubygem-rack: Possible Denial of Service Vulnerability in Rack Header Parsing (CVE-2024-26146)</li> <li> rubygem-rack: Possible DoS Vulnerability with Range Header in Rack (CVE-2024-26141)</li> <li> rubygem-rack: Denial of Service Vulnerability in Rack Content-Type Parsing (CVE-2024-25126)</li> <li> python-ecdsa: vulnerable to the Minerva attack (CVE-2024-23342)</li> Users of Red Hat Satellite are advised to upgrade to these updated<br>packages, which fix these bugs.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:10806?
The severity of RHSA-2024:10806 is categorized as moderate.
How do I fix RHSA-2024:10806?
To resolve RHSA-2024:10806, install the specified packages in the provided versions, such as satellite 6.15.5-1.el8.
Which products are affected by RHSA-2024:10806?
RHSA-2024:10806 affects Red Hat Satellite, Red Hat Satellite Capsule, and various related packages.
Is there a workaround for RHSA-2024:10806?
There is no documented workaround for RHSA-2024:10806; applying the updates is the recommended approach.
What versions of packages should be updated for RHSA-2024:10806?
For RHSA-2024:10806, specific package versions include satellite 6.15.5-1.el8 and others mentioned in the advisory.