RHEL 7 : Satellite 6.7 . (Important) (RHSA-2020:1454)

high Nessus Plugin ID 136038

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2020:1454 advisory.

Red Hat Satellite is a systems management tool for Linux-based infrastructure. It allows for provisioning, remote management, and monitoring of multiple Linux deployments with a single centralized tool.

Security Fix(es):

* apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)

* jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server (CVE-2019-12086)

* mina-core: Retaining an open socket in close_notify SSL-TLS leading to Information disclosure (CVE-2019-0231)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

* Ansible Runner is now the default way to utilize Ansible for remote execution jobs.

* Users now have the ability to log into hosts using the Web Console directly from the Satellite UI.

* Azure has been added to the list of supported compute resources for provisioning along with many bug fixes for Google Compute, RHEV, VMWare, and Kubevirt.

* Content views have been improved with many bug fixes, performance improvement, and the addition of filtering on modules.

* Content syncing has been improved with many fixes, and the ability to add proxy definitions to each product in Satellite.

* The installation process has been improved to include better tuning defaults and several other bug fixes.

* Subscription Management has been improved with many bug fixes in Satellite, new reporting, as well as in the inventory upload plugin which allows customers to view their inventory in Subscription Watch at cloud.redhat.com

* Security improvements include the ability to impersonate another user, and the introduction of integration with Red Hat SSO using openid connect.

The items above are not a complete list of changes. This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1378442

https://bugzilla.redhat.com/show_bug.cgi?id=1424922

https://bugzilla.redhat.com/show_bug.cgi?id=1468388

https://bugzilla.redhat.com/show_bug.cgi?id=1468742

https://bugzilla.redhat.com/show_bug.cgi?id=1474311

https://bugzilla.redhat.com/show_bug.cgi?id=1479765

https://bugzilla.redhat.com/show_bug.cgi?id=1486353

https://bugzilla.redhat.com/show_bug.cgi?id=1495335

https://bugzilla.redhat.com/show_bug.cgi?id=1503059

https://bugzilla.redhat.com/show_bug.cgi?id=1511254

https://bugzilla.redhat.com/show_bug.cgi?id=1517257

https://bugzilla.redhat.com/show_bug.cgi?id=1528193

https://bugzilla.redhat.com/show_bug.cgi?id=1535579

https://bugzilla.redhat.com/show_bug.cgi?id=1537555

https://bugzilla.redhat.com/show_bug.cgi?id=1541481

https://bugzilla.redhat.com/show_bug.cgi?id=1561796

https://bugzilla.redhat.com/show_bug.cgi?id=1567784

https://bugzilla.redhat.com/show_bug.cgi?id=1568046

https://bugzilla.redhat.com/show_bug.cgi?id=1571210

https://bugzilla.redhat.com/show_bug.cgi?id=1574526

https://bugzilla.redhat.com/show_bug.cgi?id=1578911

https://bugzilla.redhat.com/show_bug.cgi?id=1590854

https://bugzilla.redhat.com/show_bug.cgi?id=1591908

https://bugzilla.redhat.com/show_bug.cgi?id=1596882

https://bugzilla.redhat.com/show_bug.cgi?id=1597246

https://bugzilla.redhat.com/show_bug.cgi?id=1599313

https://bugzilla.redhat.com/show_bug.cgi?id=1607550

https://bugzilla.redhat.com/show_bug.cgi?id=1609823

https://bugzilla.redhat.com/show_bug.cgi?id=1619533

https://bugzilla.redhat.com/show_bug.cgi?id=1624424

https://bugzilla.redhat.com/show_bug.cgi?id=1625115

https://bugzilla.redhat.com/show_bug.cgi?id=1628782

https://bugzilla.redhat.com/show_bug.cgi?id=1631712

https://bugzilla.redhat.com/show_bug.cgi?id=1631812

https://bugzilla.redhat.com/show_bug.cgi?id=1634760

https://bugzilla.redhat.com/show_bug.cgi?id=1635093

https://bugzilla.redhat.com/show_bug.cgi?id=1637777

https://bugzilla.redhat.com/show_bug.cgi?id=1639696

https://bugzilla.redhat.com/show_bug.cgi?id=1639952

https://bugzilla.redhat.com/show_bug.cgi?id=1641223

https://bugzilla.redhat.com/show_bug.cgi?id=1642171

https://bugzilla.redhat.com/show_bug.cgi?id=1643530

https://bugzilla.redhat.com/show_bug.cgi?id=1645275

https://bugzilla.redhat.com/show_bug.cgi?id=1646357

https://bugzilla.redhat.com/show_bug.cgi?id=1651660

https://bugzilla.redhat.com/show_bug.cgi?id=1651799

https://bugzilla.redhat.com/show_bug.cgi?id=1658566

https://bugzilla.redhat.com/show_bug.cgi?id=1659414

https://bugzilla.redhat.com/show_bug.cgi?id=1661471

https://bugzilla.redhat.com/show_bug.cgi?id=1662212

https://bugzilla.redhat.com/show_bug.cgi?id=1732657

https://bugzilla.redhat.com/show_bug.cgi?id=1732707

https://bugzilla.redhat.com/show_bug.cgi?id=1734359

https://bugzilla.redhat.com/show_bug.cgi?id=1734776

https://bugzilla.redhat.com/show_bug.cgi?id=1734808

https://bugzilla.redhat.com/show_bug.cgi?id=1736179

https://bugzilla.redhat.com/show_bug.cgi?id=1737418

https://bugzilla.redhat.com/show_bug.cgi?id=1738472

https://bugzilla.redhat.com/show_bug.cgi?id=1739074

https://bugzilla.redhat.com/show_bug.cgi?id=1741011

https://bugzilla.redhat.com/show_bug.cgi?id=1741275

https://bugzilla.redhat.com/show_bug.cgi?id=1741847

https://bugzilla.redhat.com/show_bug.cgi?id=1742195

https://bugzilla.redhat.com/show_bug.cgi?id=1743254

https://bugzilla.redhat.com/show_bug.cgi?id=1743481

https://bugzilla.redhat.com/show_bug.cgi?id=1744528

https://bugzilla.redhat.com/show_bug.cgi?id=1745494

https://bugzilla.redhat.com/show_bug.cgi?id=1745835

https://bugzilla.redhat.com/show_bug.cgi?id=1746780

https://bugzilla.redhat.com/show_bug.cgi?id=1747512

https://bugzilla.redhat.com/show_bug.cgi?id=1747566

https://bugzilla.redhat.com/show_bug.cgi?id=1747581

https://bugzilla.redhat.com/show_bug.cgi?id=1749233

https://bugzilla.redhat.com/show_bug.cgi?id=1750030

https://bugzilla.redhat.com/show_bug.cgi?id=1750248

https://bugzilla.redhat.com/show_bug.cgi?id=1750811

https://bugzilla.redhat.com/show_bug.cgi?id=1750924

https://bugzilla.redhat.com/show_bug.cgi?id=1752436

https://bugzilla.redhat.com/show_bug.cgi?id=1753125

https://bugzilla.redhat.com/show_bug.cgi?id=1753313

https://bugzilla.redhat.com/show_bug.cgi?id=1754314

https://bugzilla.redhat.com/show_bug.cgi?id=1754424

https://bugzilla.redhat.com/show_bug.cgi?id=1754465

https://bugzilla.redhat.com/show_bug.cgi?id=1754598

https://bugzilla.redhat.com/show_bug.cgi?id=1754864

https://bugzilla.redhat.com/show_bug.cgi?id=1755451

https://bugzilla.redhat.com/show_bug.cgi?id=1755614

https://bugzilla.redhat.com/show_bug.cgi?id=1755864

https://bugzilla.redhat.com/show_bug.cgi?id=1756955

https://bugzilla.redhat.com/show_bug.cgi?id=1758250

https://bugzilla.redhat.com/show_bug.cgi?id=1758645

https://bugzilla.redhat.com/show_bug.cgi?id=1762793

https://bugzilla.redhat.com/show_bug.cgi?id=1762858

https://bugzilla.redhat.com/show_bug.cgi?id=1763283

https://bugzilla.redhat.com/show_bug.cgi?id=1763837

https://bugzilla.redhat.com/show_bug.cgi?id=1763884

https://bugzilla.redhat.com/show_bug.cgi?id=1763893

https://bugzilla.redhat.com/show_bug.cgi?id=1764625

https://bugzilla.redhat.com/show_bug.cgi?id=1765610

https://bugzilla.redhat.com/show_bug.cgi?id=1766199

https://bugzilla.redhat.com/show_bug.cgi?id=1766344

https://bugzilla.redhat.com/show_bug.cgi?id=1766529

https://bugzilla.redhat.com/show_bug.cgi?id=1766919

https://bugzilla.redhat.com/show_bug.cgi?id=1766947

https://bugzilla.redhat.com/show_bug.cgi?id=1766948

https://bugzilla.redhat.com/show_bug.cgi?id=1767483

https://bugzilla.redhat.com/show_bug.cgi?id=1769251

https://bugzilla.redhat.com/show_bug.cgi?id=1770044

https://bugzilla.redhat.com/show_bug.cgi?id=1770383

https://bugzilla.redhat.com/show_bug.cgi?id=1770384

https://bugzilla.redhat.com/show_bug.cgi?id=1770393

https://bugzilla.redhat.com/show_bug.cgi?id=1770394

https://bugzilla.redhat.com/show_bug.cgi?id=1770430

https://bugzilla.redhat.com/show_bug.cgi?id=1770431

https://bugzilla.redhat.com/show_bug.cgi?id=1770433

https://bugzilla.redhat.com/show_bug.cgi?id=1781176

https://bugzilla.redhat.com/show_bug.cgi?id=1781183

https://bugzilla.redhat.com/show_bug.cgi?id=1781186

https://bugzilla.redhat.com/show_bug.cgi?id=1781340

https://bugzilla.redhat.com/show_bug.cgi?id=1781402

https://bugzilla.redhat.com/show_bug.cgi?id=1781546

https://bugzilla.redhat.com/show_bug.cgi?id=1781766

https://bugzilla.redhat.com/show_bug.cgi?id=1781794

https://bugzilla.redhat.com/show_bug.cgi?id=1782075

http://www.nessus.org/u?965eb8a1

https://access.redhat.com/security/updates/classification/#important

https://access.redhat.com/errata/RHSA-2020:1454

https://bugzilla.redhat.com/show_bug.cgi?id=1201146

https://bugzilla.redhat.com/show_bug.cgi?id=1215390

https://bugzilla.redhat.com/show_bug.cgi?id=1336437

https://bugzilla.redhat.com/show_bug.cgi?id=1343707

https://bugzilla.redhat.com/show_bug.cgi?id=1367549

https://bugzilla.redhat.com/show_bug.cgi?id=1662492

https://bugzilla.redhat.com/show_bug.cgi?id=1663214

https://bugzilla.redhat.com/show_bug.cgi?id=1665134

https://bugzilla.redhat.com/show_bug.cgi?id=1667105

https://bugzilla.redhat.com/show_bug.cgi?id=1667973

https://bugzilla.redhat.com/show_bug.cgi?id=1668052

https://bugzilla.redhat.com/show_bug.cgi?id=1670109

https://bugzilla.redhat.com/show_bug.cgi?id=1670463

https://bugzilla.redhat.com/show_bug.cgi?id=1672648

https://bugzilla.redhat.com/show_bug.cgi?id=1677282

https://bugzilla.redhat.com/show_bug.cgi?id=1678179

https://bugzilla.redhat.com/show_bug.cgi?id=1679593

https://bugzilla.redhat.com/show_bug.cgi?id=1680112

https://bugzilla.redhat.com/show_bug.cgi?id=1684531

https://bugzilla.redhat.com/show_bug.cgi?id=1687341

https://bugzilla.redhat.com/show_bug.cgi?id=1687520

https://bugzilla.redhat.com/show_bug.cgi?id=1687771

https://bugzilla.redhat.com/show_bug.cgi?id=1691453

https://bugzilla.redhat.com/show_bug.cgi?id=1692753

https://bugzilla.redhat.com/show_bug.cgi?id=1693249

https://bugzilla.redhat.com/show_bug.cgi?id=1694093

https://bugzilla.redhat.com/show_bug.cgi?id=1695645

https://bugzilla.redhat.com/show_bug.cgi?id=1696086

https://bugzilla.redhat.com/show_bug.cgi?id=1696625

https://bugzilla.redhat.com/show_bug.cgi?id=1698151

https://bugzilla.redhat.com/show_bug.cgi?id=1698154

https://bugzilla.redhat.com/show_bug.cgi?id=1698158

https://bugzilla.redhat.com/show_bug.cgi?id=1698176

https://bugzilla.redhat.com/show_bug.cgi?id=1698181

https://bugzilla.redhat.com/show_bug.cgi?id=1700016

https://bugzilla.redhat.com/show_bug.cgi?id=1700501

https://bugzilla.redhat.com/show_bug.cgi?id=1700769

https://bugzilla.redhat.com/show_bug.cgi?id=1701062

https://bugzilla.redhat.com/show_bug.cgi?id=1701942

https://bugzilla.redhat.com/show_bug.cgi?id=1703096

https://bugzilla.redhat.com/show_bug.cgi?id=1703175

https://bugzilla.redhat.com/show_bug.cgi?id=1703490

https://bugzilla.redhat.com/show_bug.cgi?id=1705968

https://bugzilla.redhat.com/show_bug.cgi?id=1710555

https://bugzilla.redhat.com/show_bug.cgi?id=1711465

https://bugzilla.redhat.com/show_bug.cgi?id=1712015

https://bugzilla.redhat.com/show_bug.cgi?id=1713468

https://bugzilla.redhat.com/show_bug.cgi?id=1714537

https://bugzilla.redhat.com/show_bug.cgi?id=1717374

https://bugzilla.redhat.com/show_bug.cgi?id=1718077

https://bugzilla.redhat.com/show_bug.cgi?id=1718988

https://bugzilla.redhat.com/show_bug.cgi?id=1719175

https://bugzilla.redhat.com/show_bug.cgi?id=1719636

https://bugzilla.redhat.com/show_bug.cgi?id=1720141

https://bugzilla.redhat.com/show_bug.cgi?id=1720904

https://bugzilla.redhat.com/show_bug.cgi?id=1721679

https://bugzilla.redhat.com/show_bug.cgi?id=1721848

https://bugzilla.redhat.com/show_bug.cgi?id=1722841

https://bugzilla.redhat.com/show_bug.cgi?id=1723670

https://bugzilla.redhat.com/show_bug.cgi?id=1725957

https://bugzilla.redhat.com/show_bug.cgi?id=1725958

https://bugzilla.redhat.com/show_bug.cgi?id=1726139

https://bugzilla.redhat.com/show_bug.cgi?id=1728612

https://bugzilla.redhat.com/show_bug.cgi?id=1728655

https://bugzilla.redhat.com/show_bug.cgi?id=1728671

https://bugzilla.redhat.com/show_bug.cgi?id=1729179

https://bugzilla.redhat.com/show_bug.cgi?id=1729364

https://bugzilla.redhat.com/show_bug.cgi?id=1730371

https://bugzilla.redhat.com/show_bug.cgi?id=1730375

https://bugzilla.redhat.com/show_bug.cgi?id=1730752

https://bugzilla.redhat.com/show_bug.cgi?id=1731136

https://bugzilla.redhat.com/show_bug.cgi?id=1731373

https://bugzilla.redhat.com/show_bug.cgi?id=1731516

https://bugzilla.redhat.com/show_bug.cgi?id=1732056

https://bugzilla.redhat.com/show_bug.cgi?id=1770584

https://bugzilla.redhat.com/show_bug.cgi?id=1770646

https://bugzilla.redhat.com/show_bug.cgi?id=1770669

https://bugzilla.redhat.com/show_bug.cgi?id=1770999

https://bugzilla.redhat.com/show_bug.cgi?id=1771092

https://bugzilla.redhat.com/show_bug.cgi?id=1771334

https://bugzilla.redhat.com/show_bug.cgi?id=1771404

https://bugzilla.redhat.com/show_bug.cgi?id=1771419

https://bugzilla.redhat.com/show_bug.cgi?id=1771421

https://bugzilla.redhat.com/show_bug.cgi?id=1771425

https://bugzilla.redhat.com/show_bug.cgi?id=1771453

https://bugzilla.redhat.com/show_bug.cgi?id=1771507

https://bugzilla.redhat.com/show_bug.cgi?id=1771508

https://bugzilla.redhat.com/show_bug.cgi?id=1771528

https://bugzilla.redhat.com/show_bug.cgi?id=1771719

https://bugzilla.redhat.com/show_bug.cgi?id=1771905

https://bugzilla.redhat.com/show_bug.cgi?id=1771937

https://bugzilla.redhat.com/show_bug.cgi?id=1772024

https://bugzilla.redhat.com/show_bug.cgi?id=1772029

https://bugzilla.redhat.com/show_bug.cgi?id=1772079

https://bugzilla.redhat.com/show_bug.cgi?id=1772199

https://bugzilla.redhat.com/show_bug.cgi?id=1772323

https://bugzilla.redhat.com/show_bug.cgi?id=1772349

https://bugzilla.redhat.com/show_bug.cgi?id=1772398

https://bugzilla.redhat.com/show_bug.cgi?id=1772403

https://bugzilla.redhat.com/show_bug.cgi?id=1772857

https://bugzilla.redhat.com/show_bug.cgi?id=1773133

https://bugzilla.redhat.com/show_bug.cgi?id=1773146

https://bugzilla.redhat.com/show_bug.cgi?id=1773472

https://bugzilla.redhat.com/show_bug.cgi?id=1773584

https://bugzilla.redhat.com/show_bug.cgi?id=1773601

https://bugzilla.redhat.com/show_bug.cgi?id=1774083

https://bugzilla.redhat.com/show_bug.cgi?id=1774324

https://bugzilla.redhat.com/show_bug.cgi?id=1774327

https://bugzilla.redhat.com/show_bug.cgi?id=1774953

https://bugzilla.redhat.com/show_bug.cgi?id=1775274

https://bugzilla.redhat.com/show_bug.cgi?id=1775616

https://bugzilla.redhat.com/show_bug.cgi?id=1775889

https://bugzilla.redhat.com/show_bug.cgi?id=1775890

https://bugzilla.redhat.com/show_bug.cgi?id=1776002

https://bugzilla.redhat.com/show_bug.cgi?id=1776081

https://bugzilla.redhat.com/show_bug.cgi?id=1776108

https://bugzilla.redhat.com/show_bug.cgi?id=1776117

https://bugzilla.redhat.com/show_bug.cgi?id=1776151

https://bugzilla.redhat.com/show_bug.cgi?id=1776283

https://bugzilla.redhat.com/show_bug.cgi?id=1776381

https://bugzilla.redhat.com/show_bug.cgi?id=1776387

https://bugzilla.redhat.com/show_bug.cgi?id=1776754

https://bugzilla.redhat.com/show_bug.cgi?id=1776900

https://bugzilla.redhat.com/show_bug.cgi?id=1776927

https://bugzilla.redhat.com/show_bug.cgi?id=1777027

https://bugzilla.redhat.com/show_bug.cgi?id=1777191

https://bugzilla.redhat.com/show_bug.cgi?id=1777306

https://bugzilla.redhat.com/show_bug.cgi?id=1777522

https://bugzilla.redhat.com/show_bug.cgi?id=1777713

https://bugzilla.redhat.com/show_bug.cgi?id=1777720

https://bugzilla.redhat.com/show_bug.cgi?id=1777730

https://bugzilla.redhat.com/show_bug.cgi?id=1777908

https://bugzilla.redhat.com/show_bug.cgi?id=1777910

https://bugzilla.redhat.com/show_bug.cgi?id=1777992

https://bugzilla.redhat.com/show_bug.cgi?id=1778139

https://bugzilla.redhat.com/show_bug.cgi?id=1778146

https://bugzilla.redhat.com/show_bug.cgi?id=1778174

https://bugzilla.redhat.com/show_bug.cgi?id=1778177

https://bugzilla.redhat.com/show_bug.cgi?id=1778181

https://bugzilla.redhat.com/show_bug.cgi?id=1778184

https://bugzilla.redhat.com/show_bug.cgi?id=1778242

https://bugzilla.redhat.com/show_bug.cgi?id=1778599

https://bugzilla.redhat.com/show_bug.cgi?id=1778764

https://bugzilla.redhat.com/show_bug.cgi?id=1779003

https://bugzilla.redhat.com/show_bug.cgi?id=1779004

https://bugzilla.redhat.com/show_bug.cgi?id=1782131

https://bugzilla.redhat.com/show_bug.cgi?id=1782524

https://bugzilla.redhat.com/show_bug.cgi?id=1782593

https://bugzilla.redhat.com/show_bug.cgi?id=1782792

https://bugzilla.redhat.com/show_bug.cgi?id=1782807

https://bugzilla.redhat.com/show_bug.cgi?id=1783995

https://bugzilla.redhat.com/show_bug.cgi?id=1784165

https://bugzilla.redhat.com/show_bug.cgi?id=1784295

https://bugzilla.redhat.com/show_bug.cgi?id=1784454

https://bugzilla.redhat.com/show_bug.cgi?id=1784482

https://bugzilla.redhat.com/show_bug.cgi?id=1785284

https://bugzilla.redhat.com/show_bug.cgi?id=1785576

https://bugzilla.redhat.com/show_bug.cgi?id=1785613

https://bugzilla.redhat.com/show_bug.cgi?id=1785620

https://bugzilla.redhat.com/show_bug.cgi?id=1785633

https://bugzilla.redhat.com/show_bug.cgi?id=1785654

https://bugzilla.redhat.com/show_bug.cgi?id=1786114

https://bugzilla.redhat.com/show_bug.cgi?id=1786283

https://bugzilla.redhat.com/show_bug.cgi?id=1786700

https://bugzilla.redhat.com/show_bug.cgi?id=1787147

https://bugzilla.redhat.com/show_bug.cgi?id=1787330

https://bugzilla.redhat.com/show_bug.cgi?id=1787355

https://bugzilla.redhat.com/show_bug.cgi?id=1787729

https://bugzilla.redhat.com/show_bug.cgi?id=1788969

https://bugzilla.redhat.com/show_bug.cgi?id=1789013

https://bugzilla.redhat.com/show_bug.cgi?id=1779009

https://bugzilla.redhat.com/show_bug.cgi?id=1779012

https://bugzilla.redhat.com/show_bug.cgi?id=1779302

https://bugzilla.redhat.com/show_bug.cgi?id=1779653

https://bugzilla.redhat.com/show_bug.cgi?id=1779689

https://bugzilla.redhat.com/show_bug.cgi?id=1779971

https://bugzilla.redhat.com/show_bug.cgi?id=1780056

https://bugzilla.redhat.com/show_bug.cgi?id=1780108

https://bugzilla.redhat.com/show_bug.cgi?id=1780246

https://bugzilla.redhat.com/show_bug.cgi?id=1781016

https://bugzilla.redhat.com/show_bug.cgi?id=1781017

https://bugzilla.redhat.com/show_bug.cgi?id=1781080

https://bugzilla.redhat.com/show_bug.cgi?id=1789240

https://bugzilla.redhat.com/show_bug.cgi?id=1789309

https://bugzilla.redhat.com/show_bug.cgi?id=1789426

https://bugzilla.redhat.com/show_bug.cgi?id=1789654

https://bugzilla.redhat.com/show_bug.cgi?id=1789665

https://bugzilla.redhat.com/show_bug.cgi?id=1789676

https://bugzilla.redhat.com/show_bug.cgi?id=1789838

https://bugzilla.redhat.com/show_bug.cgi?id=1790184

https://bugzilla.redhat.com/show_bug.cgi?id=1791276

https://bugzilla.redhat.com/show_bug.cgi?id=1791819

https://bugzilla.redhat.com/show_bug.cgi?id=1792018

https://bugzilla.redhat.com/show_bug.cgi?id=1792836

https://bugzilla.redhat.com/show_bug.cgi?id=1793092

https://bugzilla.redhat.com/show_bug.cgi?id=1793388

https://bugzilla.redhat.com/show_bug.cgi?id=1793701

https://bugzilla.redhat.com/show_bug.cgi?id=1793872

https://bugzilla.redhat.com/show_bug.cgi?id=1794744

https://bugzilla.redhat.com/show_bug.cgi?id=1796258

https://bugzilla.redhat.com/show_bug.cgi?id=1798458

https://bugzilla.redhat.com/show_bug.cgi?id=1799027

https://bugzilla.redhat.com/show_bug.cgi?id=1800339

https://bugzilla.redhat.com/show_bug.cgi?id=1800681

https://bugzilla.redhat.com/show_bug.cgi?id=1801622

https://bugzilla.redhat.com/show_bug.cgi?id=1802036

https://bugzilla.redhat.com/show_bug.cgi?id=1802229

https://bugzilla.redhat.com/show_bug.cgi?id=1802244

https://bugzilla.redhat.com/show_bug.cgi?id=1802302

https://bugzilla.redhat.com/show_bug.cgi?id=1803792

https://bugzilla.redhat.com/show_bug.cgi?id=1804060

https://bugzilla.redhat.com/show_bug.cgi?id=1804661

https://bugzilla.redhat.com/show_bug.cgi?id=1804977

https://bugzilla.redhat.com/show_bug.cgi?id=1805313

https://bugzilla.redhat.com/show_bug.cgi?id=1805624

https://bugzilla.redhat.com/show_bug.cgi?id=1805642

https://bugzilla.redhat.com/show_bug.cgi?id=1805751

https://bugzilla.redhat.com/show_bug.cgi?id=1806196

https://bugzilla.redhat.com/show_bug.cgi?id=1807541

https://bugzilla.redhat.com/show_bug.cgi?id=1809051

Plugin Details

Severity: High

ID: 136038

File Name: redhat-RHSA-2020-1454.nasl

Version: 1.13

Type: local

Agent: unix

Published: 4/28/2020

Updated: 11/7/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-10086

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2019-12086

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:python2-lockfile, p-cpe:/a:redhat:enterprise_linux:python-yarl, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_discovery_image, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ovirt-engine-sdk, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-multi_json, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-locale, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-safemode, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-bcrypt, p-cpe:/a:redhat:enterprise_linux:foreman-postgresql, p-cpe:/a:redhat:enterprise_linux:rubygem-multi_json, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-rails-i18n, p-cpe:/a:redhat:enterprise_linux:satellite-debug-tools, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-sinatra, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-coffee-script-source, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-runcible, p-cpe:/a:redhat:enterprise_linux:python-jinja2, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-loofah, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-redhat_access_lib, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-rack-cors, p-cpe:/a:redhat:enterprise_linux:libwebsockets, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-unf, p-cpe:/a:redhat:enterprise_linux:rubygem-rack-protection, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_inventory_upload, p-cpe:/a:redhat:enterprise_linux:foreman-installer, p-cpe:/a:redhat:enterprise_linux:puppetserver, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-audited, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-rbvmomi, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-diffy, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-builder, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-actionmailer, p-cpe:/a:redhat:enterprise_linux:python3-idna-ssl, p-cpe:/a:redhat:enterprise_linux:rubygem-logging-journald, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-statsd-instrument, p-cpe:/a:redhat:enterprise_linux:qpid-cpp-client, p-cpe:/a:redhat:enterprise_linux:foreman-proxy-journald, p-cpe:/a:redhat:enterprise_linux:python-aiohttp, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-recursive-open-struct, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-public_suffix, p-cpe:/a:redhat:enterprise_linux:repoview, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_tasks, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-core, p-cpe:/a:redhat:enterprise_linux:pulp-server, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-ovirt, p-cpe:/a:redhat:enterprise_linux:mod_xsendfile, p-cpe:/a:redhat:enterprise_linux:python3-six, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-railties, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-secure_headers, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-record_tag_helper, p-cpe:/a:redhat:enterprise_linux:python-simplejson, p-cpe:/a:redhat:enterprise_linux:python-async-timeout, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-xml, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_virt_who_configure, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-httpclient, p-cpe:/a:redhat:enterprise_linux:katello-selinux, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-netrc, p-cpe:/a:redhat:enterprise_linux:rubygem-kafo_wizards, p-cpe:/a:redhat:enterprise_linux:rubygem-rake, p-cpe:/a:redhat:enterprise_linux:qpid-cpp-client-devel, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-retriable, p-cpe:/a:redhat:enterprise_linux:python2-ansible-runner, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_azure_rm, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-polyglot, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-concurrent-ruby-edge, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-multipart-post, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-execjs, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-git, p-cpe:/a:redhat:enterprise_linux:pulp-nodes-common, p-cpe:/a:redhat:enterprise_linux:pulp-ostree, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_remote_execution-cockpit, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ipaddress, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman, p-cpe:/a:redhat:enterprise_linux:puppetlabs-stdlib, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-scoped_search, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-http_parser.rb, p-cpe:/a:redhat:enterprise_linux:pulp-docker-admin-extensions, p-cpe:/a:redhat:enterprise_linux:rubygem-highline, p-cpe:/a:redhat:enterprise_linux:python2-werkzeug, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-domain_name, p-cpe:/a:redhat:enterprise_linux:foreman-journald, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-mimemagic, p-cpe:/a:redhat:enterprise_linux:python-cchardet, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-activejob, p-cpe:/a:redhat:enterprise_linux:rubygem-faraday_middleware, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fast_gettext, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_hooks, p-cpe:/a:redhat:enterprise_linux:qpid-tools, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-net-ssh-krb, p-cpe:/a:redhat:enterprise_linux:foreman-gce, p-cpe:/a:redhat:enterprise_linux:ansible-runner, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ms_rest_azure, p-cpe:/a:redhat:enterprise_linux:python-typing-extensions, p-cpe:/a:redhat:enterprise_linux:python-pymongo-gridfs, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-google, p-cpe:/a:redhat:enterprise_linux:rubygem-net-ssh, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-sexp_processor, p-cpe:/a:redhat:enterprise_linux:rubygem-journald-logger, p-cpe:/a:redhat:enterprise_linux:rubygem-rack, p-cpe:/a:redhat:enterprise_linux:python-six, p-cpe:/a:redhat:enterprise_linux:satellite, p-cpe:/a:redhat:enterprise_linux:rubygem-passenger-native, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-memoist, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-mail, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-dynflow, p-cpe:/a:redhat:enterprise_linux:python2-keycloak-httpd-client-install, p-cpe:/a:redhat:enterprise_linux:foreman-ec2, p-cpe:/a:redhat:enterprise_linux:python3-yarl, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_katello, p-cpe:/a:redhat:enterprise_linux:katello-service, p-cpe:/a:redhat:enterprise_linux:python-crane, p-cpe:/a:redhat:enterprise_linux:python-pycurl, p-cpe:/a:redhat:enterprise_linux:python-qpid-qmf, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-sprockets-rails, p-cpe:/a:redhat:enterprise_linux:qpid-dispatch-tools, p-cpe:/a:redhat:enterprise_linux:foreman-ovirt, p-cpe:/a:redhat:enterprise_linux:python2-vine, p-cpe:/a:redhat:enterprise_linux:rubygem-passenger-native-libs, p-cpe:/a:redhat:enterprise_linux:livecd-tools, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-marcel, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-rack-test, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-crass, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-journald-native, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ruby_parser, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-qpid_messaging, p-cpe:/a:redhat:enterprise_linux:katello, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-actioncable, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-pulp_rpm_client, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-roadie-rails, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-rack-jsonp, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-smart_proxy_dynflow_core, p-cpe:/a:redhat:enterprise_linux:python-idna, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-katello, p-cpe:/a:redhat:enterprise_linux:python-receptor-satellite, p-cpe:/a:redhat:enterprise_linux:rubygem-gssapi, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_ansible_core, p-cpe:/a:redhat:enterprise_linux:python2-anyjson, p-cpe:/a:redhat:enterprise_linux:gofer, p-cpe:/a:redhat:enterprise_linux:python3-multidict, p-cpe:/a:redhat:enterprise_linux:python2-pexpect, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-bundler_ext, p-cpe:/a:redhat:enterprise_linux:foreman-telemetry, p-cpe:/a:redhat:enterprise_linux:python-psutil, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_bootdisk, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-erubi, p-cpe:/a:redhat:enterprise_linux:python-blinker, p-cpe:/a:redhat:enterprise_linux:python2-okaara, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_dhcp_infoblox, p-cpe:/a:redhat:enterprise_linux:python-twisted, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_ansible, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-net-ping, p-cpe:/a:redhat:enterprise_linux:rubygem-concurrent-ruby, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ms_rest, p-cpe:/a:redhat:enterprise_linux:rubygem-fast_gettext, p-cpe:/a:redhat:enterprise_linux:rubygem-logging, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-webpack-rails, p-cpe:/a:redhat:enterprise_linux:python2-click, p-cpe:/a:redhat:enterprise_linux:ansiblerole-satellite-receptor-installer, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-json, p-cpe:/a:redhat:enterprise_linux:python-bson, p-cpe:/a:redhat:enterprise_linux:python-gnupg, p-cpe:/a:redhat:enterprise_linux:python-lockfile, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-coffee-rails, p-cpe:/a:redhat:enterprise_linux:foreman-vmware, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-kubevirt, p-cpe:/a:redhat:enterprise_linux:rubygem-newt, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-sqlite3, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-gettext_i18n_rails, p-cpe:/a:redhat:enterprise_linux:python3-attrs, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-gssapi, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-roadie, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-rabl, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-rails-dom-testing, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_templates, p-cpe:/a:redhat:enterprise_linux:python2-gobject, p-cpe:/a:redhat:enterprise_linux:python2-kombu, p-cpe:/a:redhat:enterprise_linux:pulp-ostree-plugins, p-cpe:/a:redhat:enterprise_linux:receptor, p-cpe:/a:redhat:enterprise_linux:pulp-docker, p-cpe:/a:redhat:enterprise_linux:createrepo_c-libs, p-cpe:/a:redhat:enterprise_linux:python-okaara, p-cpe:/a:redhat:enterprise_linux:python-pulp-puppet-common, p-cpe:/a:redhat:enterprise_linux:python3-aiohttp, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-arel, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-apipie-bindings, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-globalid, p-cpe:/a:redhat:enterprise_linux:pulp-nodes-child, p-cpe:/a:redhat:enterprise_linux:python3-idna, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-activerecord-import, p-cpe:/a:redhat:enterprise_linux:python-werkzeug, p-cpe:/a:redhat:enterprise_linux:python-multidict, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_rh_cloud, p-cpe:/a:redhat:enterprise_linux:python-pulp-oid_validation, p-cpe:/a:redhat:enterprise_linux:rubygem-bundler_ext, p-cpe:/a:redhat:enterprise_linux:pulp-docker-plugins, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-kubeclient, p-cpe:/a:redhat:enterprise_linux:tfm-runtime, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-little-plugger, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-rack-protection, p-cpe:/a:redhat:enterprise_linux:python2-twisted, p-cpe:/a:redhat:enterprise_linux:python-gofer, p-cpe:/a:redhat:enterprise_linux:python-anyjson, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_remote_execution_ssh, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-rails-html-sanitizer, p-cpe:/a:redhat:enterprise_linux:python-billiard, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-thor, p-cpe:/a:redhat:enterprise_linux:foreman-proxy, p-cpe:/a:redhat:enterprise_linux:python2-solv, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-logging, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-pulpcore_client, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-passenger, p-cpe:/a:redhat:enterprise_linux:python-semantic_version, p-cpe:/a:redhat:enterprise_linux:python-pulp-agent-lib, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-rainbow, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-quantile, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-os, p-cpe:/a:redhat:enterprise_linux:python-pulp-repoauth, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-thread_safe, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_ansible, p-cpe:/a:redhat:enterprise_linux:rubygem-jwt, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-parse-cron, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_ansible, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-awesome_print, p-cpe:/a:redhat:enterprise_linux:future, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-azure_mgmt_resources, p-cpe:/a:redhat:enterprise_linux:python-pulp-bindings, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-sprockets, p-cpe:/a:redhat:enterprise_linux:kobo, p-cpe:/a:redhat:enterprise_linux:python-idna-ssl, p-cpe:/a:redhat:enterprise_linux:rubygem-journald-native, p-cpe:/a:redhat:enterprise_linux:ansiblerole-foreman_scap_client, p-cpe:/a:redhat:enterprise_linux:python3-prometheus-client, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_admin, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-faraday-cookie_jar, p-cpe:/a:redhat:enterprise_linux:qpid-proton-c, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_discovery, p-cpe:/a:redhat:enterprise_linux:foreman-openstack, p-cpe:/a:redhat:enterprise_linux:python-qpid-proton, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-pulp_file_client, p-cpe:/a:redhat:enterprise_linux:python-pulp-docker-common, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_openscap, p-cpe:/a:redhat:enterprise_linux:tfm, p-cpe:/a:redhat:enterprise_linux:qpid-cpp-server-linearstore, p-cpe:/a:redhat:enterprise_linux:qpid-dispatch-router, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-aws, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-algebrick, p-cpe:/a:redhat:enterprise_linux:pulp-ostree-admin-extensions, p-cpe:/a:redhat:enterprise_linux:pulp-puppet-plugins, p-cpe:/a:redhat:enterprise_linux:python-flask, p-cpe:/a:redhat:enterprise_linux:python-itsdangerous, p-cpe:/a:redhat:enterprise_linux:pulp-puppet, p-cpe:/a:redhat:enterprise_linux:python-qpid, p-cpe:/a:redhat:enterprise_linux:katello-certs-tools, p-cpe:/a:redhat:enterprise_linux:foreman-debug, p-cpe:/a:redhat:enterprise_linux:rubygem-foreman_scap_client, p-cpe:/a:redhat:enterprise_linux:python2-pycurl, p-cpe:/a:redhat:enterprise_linux:python2-crane, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_remote_execution_core, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-net-ssh, p-cpe:/a:redhat:enterprise_linux:satellite-capsule, p-cpe:/a:redhat:enterprise_linux:foreman-installer-katello, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_azure_rm, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-logging-journald, p-cpe:/a:redhat:enterprise_linux:rubygem-clamp, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ruby-libvirt, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_theme_satellite, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-runtime, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_kubevirt, p-cpe:/a:redhat:enterprise_linux:tfm-ror52, p-cpe:/a:redhat:enterprise_linux:python-pexpect, p-cpe:/a:redhat:enterprise_linux:python3-typing-extensions, p-cpe:/a:redhat:enterprise_linux:pulp-puppet-admin-extensions, p-cpe:/a:redhat:enterprise_linux:python-kid, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-http-cookie, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-passenger-native-libs, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ethon, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-rbovirt, p-cpe:/a:redhat:enterprise_linux:python-oauth2, p-cpe:/a:redhat:enterprise_linux:python3-dateutil, p-cpe:/a:redhat:enterprise_linux:puppet-agent, p-cpe:/a:redhat:enterprise_linux:pycairo, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-graphql-batch, p-cpe:/a:redhat:enterprise_linux:python2-jinja2, p-cpe:/a:redhat:enterprise_linux:pygobject3, p-cpe:/a:redhat:enterprise_linux:katello-client-bootstrap, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_pulp, p-cpe:/a:redhat:enterprise_linux:python-jmespath, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_virt_who_configure, p-cpe:/a:redhat:enterprise_linux:python-pulp-common, p-cpe:/a:redhat:enterprise_linux:python2-django, p-cpe:/a:redhat:enterprise_linux:python2-billiard, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-turbolinks, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-redhat_access, p-cpe:/a:redhat:enterprise_linux:python2-ptyprocess, p-cpe:/a:redhat:enterprise_linux:rubygem-faraday, p-cpe:/a:redhat:enterprise_linux:python2-amqp, p-cpe:/a:redhat:enterprise_linux:rubygem-kafo_parsers, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-passenger-native, p-cpe:/a:redhat:enterprise_linux:saslwrapper, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman-tasks-core, p-cpe:/a:redhat:enterprise_linux:ostree, p-cpe:/a:redhat:enterprise_linux:python-pulp-streamer, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-facter, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-http, p-cpe:/a:redhat:enterprise_linux:python-pulp-client-lib, p-cpe:/a:redhat:enterprise_linux:python-pulp-integrity, p-cpe:/a:redhat:enterprise_linux:libmodulemd, p-cpe:/a:redhat:enterprise_linux:foreman-proxy-content, p-cpe:/a:redhat:enterprise_linux:rubygem-rkerberos, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-libvirt, p-cpe:/a:redhat:enterprise_linux:rubygem-infoblox, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-graphql, p-cpe:/a:redhat:enterprise_linux:python-zope-interface, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-angular-rails-templates, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-activemodel, p-cpe:/a:redhat:enterprise_linux:rubygem-rubyipmi, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_dynflow, p-cpe:/a:redhat:enterprise_linux:python2-flask, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-declarative, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_openscap, p-cpe:/a:redhat:enterprise_linux:python-markupsafe, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_remote_execution, p-cpe:/a:redhat:enterprise_linux:libsolv, p-cpe:/a:redhat:enterprise_linux:satellite-common, p-cpe:/a:redhat:enterprise_linux:pulp-selinux, p-cpe:/a:redhat:enterprise_linux:python-vine, p-cpe:/a:redhat:enterprise_linux:python-prometheus-client, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-friendly_id, p-cpe:/a:redhat:enterprise_linux:python2-jmespath, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ruby2ruby, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-actionview, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-vsphere, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-activesupport, p-cpe:/a:redhat:enterprise_linux:rubygem-passenger, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-journald-logger, p-cpe:/a:redhat:enterprise_linux:python-pymongo, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-concurrent-ruby, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-websocket-driver, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-openstack, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-fog-rackspace, p-cpe:/a:redhat:enterprise_linux:hfsplus-tools, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-jgrep, p-cpe:/a:redhat:enterprise_linux:rubygem-rest-client, p-cpe:/a:redhat:enterprise_linux:foreman-bootloaders-redhat, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-activestorage, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-representable, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-apipie-rails, p-cpe:/a:redhat:enterprise_linux:python-amqp, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-daemons, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-jwt, p-cpe:/a:redhat:enterprise_linux:python2-markupsafe, p-cpe:/a:redhat:enterprise_linux:python-pulp-rpm-common, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_templates, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_openscap, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_bootdisk, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-validates_lengths_from_database, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-activerecord-session_store, p-cpe:/a:redhat:enterprise_linux:rubygem-netrc, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hashie, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-typhoeus, p-cpe:/a:redhat:enterprise_linux:candlepin, p-cpe:/a:redhat:enterprise_linux:python-imgcreate, p-cpe:/a:redhat:enterprise_linux:rubygem-hashie, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_kubevirt, p-cpe:/a:redhat:enterprise_linux:python-attrs, p-cpe:/a:redhat:enterprise_linux:foreman-rackspace, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-rack, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-azure_mgmt_compute, p-cpe:/a:redhat:enterprise_linux:pcp-mmvstatsd, p-cpe:/a:redhat:enterprise_linux:rubygem-openscap, p-cpe:/a:redhat:enterprise_linux:python-chardet, p-cpe:/a:redhat:enterprise_linux:python3-chardet, p-cpe:/a:redhat:enterprise_linux:pulp-maintenance, p-cpe:/a:redhat:enterprise_linux:rubygem-powerbar, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman-tasks, p-cpe:/a:redhat:enterprise_linux:pulp-rpm-plugins, p-cpe:/a:redhat:enterprise_linux:python-gofer-qpid, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-robotex, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_remote_execution, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-powerbar, p-cpe:/a:redhat:enterprise_linux:python-mongoengine, p-cpe:/a:redhat:enterprise_linux:rubygem-multipart-post, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-pulp_2to3_migration_client, p-cpe:/a:redhat:enterprise_linux:ansiblerole-insights-client, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-http-form_data, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-mini_mime, p-cpe:/a:redhat:enterprise_linux:pulp-katello, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-text, p-cpe:/a:redhat:enterprise_linux:pulp-rpm-admin-extensions, p-cpe:/a:redhat:enterprise_linux:python2-gobject-base, p-cpe:/a:redhat:enterprise_linux:foreman-discovery-image, p-cpe:/a:redhat:enterprise_linux:rubygem-facter, p-cpe:/a:redhat:enterprise_linux:foreman-bootloaders-redhat-tftpboot, p-cpe:/a:redhat:enterprise_linux:rubygem-tilt, p-cpe:/a:redhat:enterprise_linux:python2-celery, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-pulp_docker_client, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-responders, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-nio4r, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-sequel, p-cpe:/a:redhat:enterprise_linux:python-celery, p-cpe:/a:redhat:enterprise_linux:python-dateutil, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-mustermann, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ffi, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-addressable, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-faraday, p-cpe:/a:redhat:enterprise_linux:pulp-rpm, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-highline, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-mime-types-data, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-unicode-display_width, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-anemone, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-i18n, p-cpe:/a:redhat:enterprise_linux:candlepin-selinux, p-cpe:/a:redhat:enterprise_linux:keycloak-httpd-client-install, p-cpe:/a:redhat:enterprise_linux:rubygem-rsec, p-cpe:/a:redhat:enterprise_linux:python-django, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-googleauth, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-css_parser, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-tzinfo, p-cpe:/a:redhat:enterprise_linux:python-ptyprocess, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-net-ldap, p-cpe:/a:redhat:enterprise_linux:foreman-cli, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-prometheus-client, p-cpe:/a:redhat:enterprise_linux:pulp-admin-client, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-actionpack, p-cpe:/a:redhat:enterprise_linux:pulp-puppet-tools, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-deacon, cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:python-pulp-ostree-common, p-cpe:/a:redhat:enterprise_linux:qpid-cpp, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-formatador, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ovirt_provision_plugin, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-timeliness, p-cpe:/a:redhat:enterprise_linux:rubygem-kafo, p-cpe:/a:redhat:enterprise_linux:qpid-qmf, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-unicode, p-cpe:/a:redhat:enterprise_linux:satellite-cli, p-cpe:/a:redhat:enterprise_linux:python2-isodate, p-cpe:/a:redhat:enterprise_linux:rubygem-rb-inotify, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-websocket-extensions, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-deface, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-clamp, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-pg, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-will_paginate, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-optimist, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-x-editable-rails, p-cpe:/a:redhat:enterprise_linux:python3-receptor-satellite, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_docker, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-unf_ext, p-cpe:/a:redhat:enterprise_linux:redhat-access-insights-puppet, p-cpe:/a:redhat:enterprise_linux:python3-cchardet, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ancestry, p-cpe:/a:redhat:enterprise_linux:pulp, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-nokogiri, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-tilt, p-cpe:/a:redhat:enterprise_linux:python-click, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-mime-types, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-mini_portile2, p-cpe:/a:redhat:enterprise_linux:rubygem-ffi, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-signet, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-google-api-client, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-azure_mgmt_storage, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-hammer_cli_foreman_discovery, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-activerecord, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-get_process_mem, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-oauth, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-apipie-params, p-cpe:/a:redhat:enterprise_linux:foreman-libvirt, p-cpe:/a:redhat:enterprise_linux:rhel8-kickstart-setup, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-net-scp, p-cpe:/a:redhat:enterprise_linux:rubygem-oauth, p-cpe:/a:redhat:enterprise_linux:puppet-foreman_scap_client, p-cpe:/a:redhat:enterprise_linux:python3-async-timeout, p-cpe:/a:redhat:enterprise_linux:foreman, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-excon, p-cpe:/a:redhat:enterprise_linux:katello-common, p-cpe:/a:redhat:enterprise_linux:qpid-cpp-server, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-coffee-script, p-cpe:/a:redhat:enterprise_linux:pulp-nodes-parent, p-cpe:/a:redhat:enterprise_linux:python2-itsdangerous, p-cpe:/a:redhat:enterprise_linux:python2-future, p-cpe:/a:redhat:enterprise_linux:python-kombu, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-pulp_ansible_client, p-cpe:/a:redhat:enterprise_linux:qpid-dispatch, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-rails, p-cpe:/a:redhat:enterprise_linux:tfm-ror52-rubygem-method_source, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-sshkey, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-deep_cloneable, p-cpe:/a:redhat:enterprise_linux:rubygem-little-plugger, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-azure_mgmt_network, p-cpe:/a:redhat:enterprise_linux:rubygem-ansi, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-declarative-option, p-cpe:/a:redhat:enterprise_linux:qpid-proton, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-rest-client, p-cpe:/a:redhat:enterprise_linux:python-nectar, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-uber, p-cpe:/a:redhat:enterprise_linux:foreman-selinux, p-cpe:/a:redhat:enterprise_linux:python-saslwrapper, p-cpe:/a:redhat:enterprise_linux:mod_passenger, p-cpe:/a:redhat:enterprise_linux:puppet-agent-oauth, p-cpe:/a:redhat:enterprise_linux:python-daemon, p-cpe:/a:redhat:enterprise_linux:rubygem-mime-types, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-ldap_fluff, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-gettext, p-cpe:/a:redhat:enterprise_linux:createrepo_c, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-promise.rb, p-cpe:/a:redhat:enterprise_linux:rubygem-sinatra, p-cpe:/a:redhat:enterprise_linux:satellite-installer, p-cpe:/a:redhat:enterprise_linux:tfm-rubygem-foreman_discovery, p-cpe:/a:redhat:enterprise_linux:python2-daemon, p-cpe:/a:redhat:enterprise_linux:python-isodate, p-cpe:/a:redhat:enterprise_linux:katello-debug, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_dhcp_remote_isc, p-cpe:/a:redhat:enterprise_linux:rubygem-smart_proxy_dns_infoblox

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/14/2020

Vulnerability Publication Date: 12/17/2017

Reference Information

CVE: CVE-2017-17718, CVE-2019-0231, CVE-2019-10086, CVE-2019-12086, CVE-2020-10716

CWE: 200, 285, 295, 319, 502

IAVA: 2020-A-0140, 2020-A-0328, 2021-A-0035-S, 2021-A-0196, 2021-A-0328

RHSA: 2020:1454