RHSA-2021:5191MediumCVSS 4.3
Red Hat Security Advisory: Red Hat 3scale API Management 2.11.1 Release - Container Images
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-26247 — rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema
🎯 Affected products21
- Red Hat 3Scale AMP 2.11
- 3scale-amp2/3scale-rhel7-operator-metadata@sha256:52beda035f75cd318b9648736bcbb5450b1201d02e24991b9f283286822fef10_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/3scale-rhel7-operator-metadata@sha256:625d03241c1774de7e73182fa3bd487b8d2a37e71223c0286cee80461424ec36_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/3scale-rhel7-operator@sha256:0eb85546aa897e620a80589c4feb17fd567cab22008c15f68856af891b82f3a3_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/3scale-rhel7-operator@sha256:2d88b59f54b3446fd1e146ed232549e8f0c0f199d05ba63c5c35a6687eab3c0d_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/apicast-gateway-rhel8@sha256:2cce2b4dd44a06c6d08ee85e6c586ee8736a8b792edfd404d857e1b80758771e_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/apicast-gateway-rhel8@sha256:e8a8bfcc5e197593fc5b597e47899ae5c8f4289d16d162e683c0b59509eb1ddd_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/apicast-rhel7-operator-metadata@sha256:3cdddf4944527a760c6b9b83a80761ca103a54bef52c29c6554b64fcf932892d_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/apicast-rhel7-operator-metadata@sha256:52814fc1073461e8b30651469b47ef9fc9fffcf26ed6f0c7a59f2cb528271df4_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/apicast-rhel7-operator@sha256:971887fcec5b0ac7f2a0920a1ed93e22087b930e19c49726721617b3a8695fcf_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/apicast-rhel7-operator@sha256:db6d0effa8860adad6b7af7140f2673c84ea371bd6ffe337591b61ad1ad11a5d_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/backend-rhel8@sha256:10818e4c115a4f6590eb452d401d96a4c43225803434608a7320bd7fa27d5019_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/backend-rhel8@sha256:2ac5e91302bd75d97fbae9192ac776a19eb48141773db4cb39ba2f907c740682_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/memcached-rhel7@sha256:c8ad2764f7847f93ddeb80abf6434db7d5e10207aa233514230064c170f0db2a_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/memcached-rhel7@sha256:e88d866f2538f3bd556715cce8d50e1310a346a679b4f1ed0e77696d0937998a_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/system-rhel7@sha256:32852c1ef328d9856012f8ae95b8ae755cd563422d24da6f36a41d3bb55a9d25_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/system-rhel7@sha256:6af9c5133729b0d13cafd5ca3852252b1d8e9298095d1a078abe6569e84fd1cb_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/toolbox-rhel8@sha256:89a7f8228a70fb6fdc0408b6e995660967ccee5b627ac3f3cc81fb64d04c7c25_ppc64le as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/toolbox-rhel8@sha256:cbff9001b7fb3af8b890a50834739a20b5fab7d186ddb3d171ebcf5abdffaebb_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/zync-rhel8@sha256:586cb426e8363239abb94ccce8c85141b26bf50e04a5a05989905f4318be80b9_amd64 as a component of Red Hat 3Scale AMP 2.11
- 3scale-amp2/zync-rhel8@sha256:8ce669e94ac7a53a4b1b608a34c65aacc1922ea572386960747e12b378900cde_ppc64le as a component of Red Hat 3Scale AMP 2.11
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_3scale_api_management/2.11/html-single/installing_3scale/index Workaround: There are no known workarounds for affected versions. Please refer to the upstream advisory page for additional information.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2021:5191
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_3scale_api_management/2.11/html-single/installing_3scale/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1912487
- externalhttps://issues.redhat.com/browse/THREESCALE-6868
- externalhttps://issues.redhat.com/browse/THREESCALE-6879
- externalhttps://issues.redhat.com/browse/THREESCALE-7030
- externalhttps://issues.redhat.com/browse/THREESCALE-7203
- externalhttps://issues.redhat.com/browse/THREESCALE-7475
- externalhttps://issues.redhat.com/browse/THREESCALE-7488
- externalhttps://issues.redhat.com/browse/THREESCALE-7573
- externalhttps://issues.redhat.com/browse/THREESCALE-7605
- externalhttps://issues.redhat.com/browse/THREESCALE-7633
- externalhttps://issues.redhat.com/browse/THREESCALE-7644
- externalhttps://issues.redhat.com/browse/THREESCALE-7646
- externalhttps://issues.redhat.com/browse/THREESCALE-7648
- externalhttps://issues.redhat.com/browse/THREESCALE-7704
- externalhttps://issues.redhat.com/browse/THREESCALE-7731
- externalhttps://issues.redhat.com/browse/THREESCALE-7761
- externalhttps://issues.redhat.com/browse/THREESCALE-7765
- externalhttps://issues.redhat.com/browse/THREESCALE-7834
- externalhttps://issues.redhat.com/browse/THREESCALE-7863
- externalhttps://issues.redhat.com/browse/THREESCALE-7884
- externalhttps://issues.redhat.com/browse/THREESCALE-7912
- externalhttps://issues.redhat.com/browse/THREESCALE-7913
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_5191.json