RHSA-2024:7987: Moderate: Satellite 6.15.4 Security Update
Moderate: Satellite 6.15.4 Security Update
Other sources
Red Hat Satellite is a system management solution that allows organizations<br>to configure and maintain their systems without the necessity to provide<br>public Internet access to their servers or other client systems. It<br>performs provisioning and configuration management of predefined standard<br>operating environments.<br>Security Fix(es):<br><li> python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headers (CVE-2024-1135)</li> <li> golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790)</li> <li> python-cryptography: NULL pointer dereference with pkcs12.serializekeyandcertificates when called with a non-matching certificate and private key and an hmachash override (CVE-2024-26130)</li> <li> python-django: Potential denial-of-service vulnerability in django.utils.html.urlize() and AdminURLFieldWidget (CVE-2024-41991)</li> Users of Red Hat Satellite are advised to upgrade to these updated<br>packages, which fix these bugs.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:7987?
The severity of RHSA-2024:7987 is classified as moderate.
How do I fix RHSA-2024:7987?
To fix RHSA-2024:7987, update the affected packages to their recommended versions as specified in the advisory.
Which products are affected by RHSA-2024:7987?
RHSA-2024:7987 affects Red Hat Satellite, Red Hat Satellite Capsule, and Red Hat Enterprise Linux for x86_64 among other related packages.
What packages need to be updated for RHSA-2024:7987?
The packages that need updating include foreman, foreman-installer, python-cryptography, and several others listed in the advisory.
When was RHSA-2024:7987 released?
RHSA-2024:7987 was released on the date specified in the advisory, which typically accompanies the announcement.