Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:1846

Опубликовано: 18 мая 2021
Источник: rocky
Оценка: Moderate

Описание

Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update

Rocky Enterprise Software Foundation Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • jquery: Passing HTML containing elements to manipulation methods could result in untrusted code execution (CVE-2020-11023)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.4 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
bind-dyndb-ldapaarch642.module+el8.4.0+429+6bd33feabind-dyndb-ldap-11.6-2.module+el8.4.0+429+6bd33fea.aarch64.rpm
custodianoarch3.module+el8.4.0+429+6bd33feacustodia-0.6.0-3.module+el8.4.0+429+6bd33fea.noarch.rpm
ipa-clientaarch643.module+el8.4.0+429+6bd33feaipa-client-4.9.2-3.module+el8.4.0+429+6bd33fea.aarch64.rpm
ipa-client-commonnoarch3.module+el8.4.0+429+6bd33feaipa-client-common-4.9.2-3.module+el8.4.0+429+6bd33fea.noarch.rpm
ipa-client-epnaarch643.module+el8.4.0+429+6bd33feaipa-client-epn-4.9.2-3.module+el8.4.0+429+6bd33fea.aarch64.rpm
ipa-client-sambaaarch643.module+el8.4.0+429+6bd33feaipa-client-samba-4.9.2-3.module+el8.4.0+429+6bd33fea.aarch64.rpm
ipa-commonnoarch3.module+el8.4.0+429+6bd33feaipa-common-4.9.2-3.module+el8.4.0+429+6bd33fea.noarch.rpm
ipa-healthchecknoarch3.module+el8.4.0+429+6bd33feaipa-healthcheck-0.7-3.module+el8.4.0+429+6bd33fea.noarch.rpm
ipa-healthcheck-corenoarch3.module+el8.4.0+429+6bd33feaipa-healthcheck-core-0.7-3.module+el8.4.0+429+6bd33fea.noarch.rpm
ipa-python-compatnoarch3.module+el8.4.0+429+6bd33feaipa-python-compat-4.9.2-3.module+el8.4.0+429+6bd33fea.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 6.9
ubuntu
больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.1
redhat
больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
nvd
больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
debian
больше 6 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, pa ...

rocky
больше 1 года назад

Moderate: gcc security update