RHSA-2024:8906CriticalCVSS 9.8

Red Hat Security Advisory: Satellite 6.16.0 release

Published
November 5, 2024
Last Modified
July 29, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2024-4067 — micromatch: vulnerable to Regular Expression Denial of Service CVE-2024-5569 — github.com/jaraco/zipp: Denial of Service (infinite loop) via crafted zip file in jaraco/zipp CVE-2024-7012 — puppet-foreman: An authentication bypass vulnerability exists in Foreman CVE-2024-7246 — grpc: client communicating with a HTTP/2 proxy can poison the HPACK table between the proxy and the backend CVE-2024-7923 — puppet-pulpcore: An authentication bypass vulnerability exists in pulpcore CVE-2024-8376 — mosquitto: sending specific sequences of packets may trigger memory leak CVE-2024-8553 — foreman: Read-only access to entire DB from templates CVE-2024-28863 — node-tar: denial of service while parsing a tar file due to lack of folders depth validation CVE-2024-37891 — urllib3: proxy-authorization request header is not stripped during cross-origin redirects CVE-2024-38875 — python-django: Potential denial-of-service in django.utils.html.urlize() CVE-2024-39329 — python-django: Username enumeration through timing difference for users with unusable passwords CVE-2024-39330 — python-django: Potential directory-traversal in django.core.files.storage.Storage.save() CVE-2024-39614 — python-django: Potential denial-of-service in django.utils.translation.get_supported_language_variant() CVE-2024-42005 — python-django: Potential SQL injection in QuerySet.values() and values_list()

🎯 Affected products200

  • Red Hat Satellite 6.16 for RHEL 8
  • Red Hat Satellite 6.16 for RHEL 9
  • ansible-collection-redhat-satellite-0:4.2.0-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansible-collection-redhat-satellite-0:4.2.0-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansible-collection-redhat-satellite-0:4.2.0-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansible-collection-redhat-satellite-0:4.2.0-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansible-collection-redhat-satellite_operations-0:3.0.0-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansible-collection-redhat-satellite_operations-0:3.0.0-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansible-collection-redhat-satellite_operations-0:3.0.0-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansible-collection-redhat-satellite_operations-0:3.0.0-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansible-lint-0:5.4.0-1.el8pc.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansible-lint-0:5.4.0-1.el8pc.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansible-runner-0:2.2.1-5.el9pc.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansible-runner-0:2.2.1-5.el9pc.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansible-runner-0:2.2.1-6.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansible-runner-0:2.2.1-6.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansiblerole-foreman_scap_client-0:0.3.0-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansiblerole-foreman_scap_client-0:0.3.0-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansiblerole-foreman_scap_client-0:0.3.0-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansiblerole-foreman_scap_client-0:0.3.0-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansiblerole-insights-client-0:1.7.1-2.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansiblerole-insights-client-0:1.7.1-2.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • ansiblerole-insights-client-0:1.7.1-2.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • ansiblerole-insights-client-0:1.7.1-2.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • candlepin-0:4.4.16-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • candlepin-0:4.4.16-1.el8sat.src as a component of Red Hat Satellite 6.16 for RHEL 8
  • candlepin-0:4.4.16-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • candlepin-0:4.4.16-1.el9sat.src as a component of Red Hat Satellite 6.16 for RHEL 9
  • candlepin-selinux-0:4.4.16-1.el8sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 8
  • candlepin-selinux-0:4.4.16-1.el9sat.noarch as a component of Red Hat Satellite 6.16 for RHEL 9
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.16/html/updating_red_hat_satellite/index Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (264)