CentOS 8 : fence-agents (CESA-2024:0133)

critical Nessus Plugin ID 187872

Synopsis

The remote CentOS host is missing one or more security updates.

Description

The remote CentOS Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the CESA-2024:0133 advisory.

- Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes e-Tugra root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from e-Tugra from the root store. (CVE-2023-37920)

- urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user.
However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5. (CVE-2023-43804)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2024:0133

Plugin Details

Severity: Critical

ID: 187872

File Name: centos8_RHSA-2024-0133.nasl

Version: 1.0

Type: local

Agent: unix

Published: 1/10/2024

Updated: 1/10/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-37920

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:centos:centos:fence-agents-openstack, p-cpe:/a:centos:centos:fence-agents-wti, p-cpe:/a:centos:centos:fence-agents-ibm-powervs, p-cpe:/a:centos:centos:fence-agents-brocade, p-cpe:/a:centos:centos:fence-agents-ilo-mp, p-cpe:/a:centos:centos:fence-agents-heuristics-ping, p-cpe:/a:centos:centos:fence-agents-rsa, p-cpe:/a:centos:centos:fence-agents-vmware-soap, p-cpe:/a:centos:centos:fence-agents-ibmblade, p-cpe:/a:centos:centos:fence-agents-mpath, p-cpe:/a:centos:centos:fence-agents-emerson, p-cpe:/a:centos:centos:fence-agents-cisco-ucs, cpe:/o:centos:centos:8-stream, p-cpe:/a:centos:centos:fence-agents-aws, p-cpe:/a:centos:centos:fence-agents-ilo2, p-cpe:/a:centos:centos:fence-agents-cisco-mds, p-cpe:/a:centos:centos:fence-agents-ibm-vpc, p-cpe:/a:centos:centos:fence-agents-drac5, p-cpe:/a:centos:centos:fence-agents-apc, p-cpe:/a:centos:centos:fence-agents-ilo-ssh, p-cpe:/a:centos:centos:fence-agents-kdump, p-cpe:/a:centos:centos:fence-agents-aliyun, p-cpe:/a:centos:centos:fence-agents-compute, cpe:/o:centos:centos:8, p-cpe:/a:centos:centos:fence-agents-hpblade, p-cpe:/a:centos:centos:fence-agents-rsb, p-cpe:/a:centos:centos:fence-agents-eaton-snmp, p-cpe:/a:centos:centos:fence-agents-all, p-cpe:/a:centos:centos:fence-agents-scsi, p-cpe:/a:centos:centos:fence-agents-ilo-moonshot, p-cpe:/a:centos:centos:fence-agents-azure-arm, p-cpe:/a:centos:centos:fence-agents-gce, p-cpe:/a:centos:centos:fence-agents-ipdu, p-cpe:/a:centos:centos:fence-agents-common, p-cpe:/a:centos:centos:fence-agents-ifmib, p-cpe:/a:centos:centos:fence-agents-apc-snmp, p-cpe:/a:centos:centos:fence-agents-rhevm, p-cpe:/a:centos:centos:fence-agents-lpar, p-cpe:/a:centos:centos:fence-agents-vmware-rest, p-cpe:/a:centos:centos:fence-agents-virsh, p-cpe:/a:centos:centos:fence-agents-sbd, p-cpe:/a:centos:centos:fence-agents-ipmilan, p-cpe:/a:centos:centos:fence-agents-kubevirt, p-cpe:/a:centos:centos:fence-agents-redfish, p-cpe:/a:centos:centos:fence-agents-amt-ws, p-cpe:/a:centos:centos:fence-agents-bladecenter, p-cpe:/a:centos:centos:fence-agents-eps, p-cpe:/a:centos:centos:fence-agents-intelmodular

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 1/10/2024

Vulnerability Publication Date: 7/25/2023

Reference Information

CVE: CVE-2023-37920, CVE-2023-43804

RHSA: 2024:0133