Описание
Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update
Rocky Enterprise Software Foundation Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.
The following packages have been upgraded to a later upstream version: ipa (4.8.7), softhsm (2.6.0), opendnssec (2.1.6). (BZ#1759888, BZ#1818765, BZ#1818877)
Security Fix(es):
-
js-jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)
-
bootstrap: XSS in the data-target attribute (CVE-2016-10735)
-
bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)
-
bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042)
-
bootstrap: XSS in the tooltip data-viewport attribute (CVE-2018-20676)
-
bootstrap: XSS in the affix configuration target property (CVE-2018-20677)
-
bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)
-
js-jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)
-
jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)
-
ipa: No password length restriction leads to denial of service (CVE-2020-1722)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.3 Release Notes linked from the References section.
Затронутые продукты
Rocky Linux 8
Ссылки на источники
Исправления
- Red Hat - 1399546
- Red Hat - 1430365
- Red Hat - 1488732
- Red Hat - 1585020
- Red Hat - 1601614
- Red Hat - 1601617
- Red Hat - 1651577
- Red Hat - 1668082
- Red Hat - 1668089
- Red Hat - 1668097
- Red Hat - 1686454
- Red Hat - 1701233
- Red Hat - 1701972
- Red Hat - 1746830
- Red Hat - 1750893
- Red Hat - 1751295
- Red Hat - 1757045
- Red Hat - 1759888
- Red Hat - 1768156
- Red Hat - 1777806
Связанные уязвимости
ELSA-2020-4670: idm:DL1 and idm:client security, bug fix, and enhancement update (MODERATE)
ELSA-2020-4670-1: idm:client security, bug fix, and enhancement update (MODERATE)
ELSA-2020-3936: ipa security, bug fix, and enhancement update (MODERATE)
ELSA-2020-4847: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (MODERATE)
Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update