Red Hat Security Advisory: pki-core security and bug fix update
🔗 CVE IDs covered (7)
📋 Description
CVE-2019-10146 — pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page CVE-2019-10179 — pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab CVE-2019-10221 — pki-core: Reflected XSS in getcookies?url= endpoint in CA CVE-2020-1721 — pki-core: KRA vulnerable to reflected XSS via the getPk12 page CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods CVE-2020-25715 — pki-core: XSS in the certificate search results CVE-2021-20179 — pki-core: Unprivileged users can renew any certificate
🎯 Affected products62
- Red Hat Enterprise Linux Client Optional (v. 7)
- Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- Red Hat Enterprise Linux Server (v. 7)
- Red Hat Enterprise Linux Server Optional (v. 7)
- Red Hat Enterprise Linux Workstation (v. 7)
- Red Hat Enterprise Linux Workstation Optional (v. 7)
- pki-base-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- pki-base-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- pki-base-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- pki-base-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- pki-base-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- pki-base-java-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- pki-base-java-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- pki-base-java-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- pki-base-java-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- pki-base-java-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- pki-ca-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- pki-ca-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- pki-ca-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- pki-ca-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- pki-ca-0:10.5.18-12.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- pki-core-0:10.5.18-12.el7_9.src as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- pki-core-0:10.5.18-12.el7_9.src as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- pki-core-0:10.5.18-12.el7_9.src as a component of Red Hat Enterprise Linux Server (v. 7)
- pki-core-0:10.5.18-12.el7_9.src as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- pki-core-0:10.5.18-12.el7_9.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
- pki-core-debuginfo-0:10.5.18-12.el7_9.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- pki-core-debuginfo-0:10.5.18-12.el7_9.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7)
- pki-core-debuginfo-0:10.5.18-12.el7_9.ppc64le as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- pki-core-debuginfo-0:10.5.18-12.el7_9.s390x as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- +32 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Because the cross-site scripting (XSS) attack requires the victim to have their RHCS certificate installed in their web browser to be successful, it is recommended that web browser not hold the keys and that the user use the command line interface (CLI) instead.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2021:0851
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1695901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1710171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1732565
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1777579
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1883639
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891016
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1914379
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0851.json