Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat CodeReady Workspaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2022:1478 - Security Advisory
Issued:
2022-04-20
Updated:
2022-04-20

RHSA-2022:1478 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Satellite 6.9.9 Async Bug Fix Update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated Satellite 6.9 packages that fix several bugs are now available for Red Hat Satellite.

Description

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments.

Security Fix(es):
2023859 CVE-2021-27023 - puppet: unsafe HTTP redirect

This update fixes the following bugs:

1929347 pulp3: Ensure migration plugin runs in FIPS mode and respects the ALLOWED_CONTENT_CHECKSUMS configuration
1992267 Incorrect puppet module count when a content view is added to the composite content view.
1998796 Pulp 3 migration failed with missing repositories.
2005392 If the migration plan is empty, all repositories get migrated.
2019563 Missing fields on MD5 repos in repomd.xml on a FIPS enabled satellite
2025804 Option "Verify Checksum" not listed under Advanced Sync Options
2027086 The katello:pulp3_migration" reports wrong failed component names if one or all pulp3 related services has failed to start during content-migration process
2027127 Pulp 2 to 3 migration fails on certain repos during the upgrade with FileNotFoundError: [Errno 2] No such file or directory: in prepare_metadata_files
2027250 CVE-2021-27023 puppetserver: puppet: unsafe HTTP redirect [rhn_satellite_6.9]
2027253 CVE-2021-27023 puppet-agent: puppet: unsafe HTTP redirect [rhn_satellite_6.9]
2032843 pulp3: 2to3 migration fails with Katello::Errors::Pulp3Error: the cursor;_django_curs_XXXX_XXXX does not exist
2033951 [Pulp3] The pulp2-3 migration fails to migrate Alma Linux BaseOS repo with error Katello::Errors::Pulp3Error: No declared artifact with relative path images boot.iso
2038739 Extremely difficult to tell what repositories to Verify Checksum on when there are hundreds or thousands of packages listed as corrupted
2038742 pulp3 content migration failed with Katello::Errors::Pulp3Error: local variable item referenced before assignment
2039059 Pulp3: Migration fails with error Katello::Errors::Pulp3Error: Empty variable tag
2039112 pulp3 migration stats drastically underestimate migration times
2043742 foreman-rake katello:approve_corrupted_migration_content fails with services
2043933 The pulp2-pulp3 migration should fail if not all the errata content has been migrated while upgrading to Satellite 6.10
2051970 pulp2to3 migration fails to migrate docker_blob content due to aggregate mongo 100M limit
2061715 Publication creation (during migration to pulp3 as well) can fail if pulp is NFS share

Users of Red Hat Satellite are advised to upgrade to these updated packages, which fix these bugs.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.9/html/upgrading_and_updating_red_hat_satellite/updating_satellite_server_capsule_server_and_content_hosts

Affected Products

  • Red Hat Satellite 6.9 x86_64
  • Red Hat Satellite Capsule 6.9 x86_64

Fixes

  • BZ - 1929347 - pulp3: Ensure migration plugin runs in FIPS mode and respects the ALLOWED_CONTENT_CHECKSUMS configuration
  • BZ - 1992267 - Incorrect puppet module count when a content view is added to the composite content view.
  • BZ - 1998796 - Pulp 3 migration failed with missing repositories.
  • BZ - 2005392 - If the migration plan is empty, all repositories get migrated.
  • BZ - 2019563 - Missing fields on MD5 repos in repomd.xml on a FIPS enabled satellite
  • BZ - 2023859 - CVE-2021-27023 puppet: unsafe HTTP redirect
  • BZ - 2025804 - Option "Verify Checksum" not listed under Advanced Sync Options
  • BZ - 2027086 - The "katello:pulp3_migration" reports wrong failed component names if one or all pulp3 related services has failed to start during content-migration process
  • BZ - 2027127 - Pulp 2 to 3 migration fails on certain repos during the upgrade with FileNotFoundError: [Errno 2] No such file or directory: '' in prepare_metadata_files
  • BZ - 2032843 - pulp3: 2to3 migration fails with Katello::Errors::Pulp3Error: the cursor "_django_curs_XXXX_XXXX" does not exist
  • BZ - 2033951 - [Pulp3] The pulp2-3 migration fails to migrate Alma Linux BaseOS repo with error Katello::Errors::Pulp3Error: No declared artifact with relative path "images/boot.iso"
  • BZ - 2038739 - Extremely difficult to tell what repositories to Verify Checksum on when there are hundreds or thousands of packages listed as corrupted
  • BZ - 2038742 - pulp3 content migration failed with "Katello::Errors::Pulp3Error: local variable 'item' referenced before assignment"
  • BZ - 2039059 - Pulp3: Migration fails with error "Katello::Errors::Pulp3Error: Empty variable tag"
  • BZ - 2039112 - pulp3 migration stats drastically underestimate migration times
  • BZ - 2043742 - foreman-rake katello:approve_corrupted_migration_content fails with services
  • BZ - 2043933 - The pulp2-pulp3 migration should fail if not all the errata content has been migrated while upgrading to Satellite 6.10
  • BZ - 2051970 - pulp2to3 migration fails to migrate docker_blob content due to aggregate mongo 100M limit
  • BZ - 2061715 - Publication creation (during migration to pulp3 as well) can fail if /var/lib/pulp is NFS share

CVEs

  • CVE-2021-27023

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Satellite 6.9

SRPM
foreman-installer-2.3.1.22-1.el7sat.src.rpm SHA-256: 2b654e1ed66b70fa45139d3f40f21e47109797cbafa957e4a4402ecc951e685a
pulp-rpm-2.21.5.2-3.el7sat.src.rpm SHA-256: d3c6624230816cace4821fb58a9d370ceb84b9600183af6a095d767733fe1816
puppet-agent-6.26.0-1.el7sat.src.rpm SHA-256: 4b54010a91ee8ffafe075b64c4003ad988d42c9316766dddd1fa73fcb4e25bfd
puppetserver-6.18.0-1.el7sat.src.rpm SHA-256: dcb912fb60c55732164584ac91ab58a4c55f09f197d4dba7e7cbf386aa6477f5
python-pulp-rpm-3.11.4-1.el7pc.src.rpm SHA-256: 8daee91928e51887defa123ab9ba1e74306f23769aaae249b52c1714d5111db2
python-pulp_2to3_migration-0.11.10-1.el7pc.src.rpm SHA-256: 3a099a93611908b2308b2ffec952502de817c8d3d16420fc24615591628d8eb9
satellite-6.9.9-1.el7sat.src.rpm SHA-256: 6e561f6afad091bd98094723dedfb3f06efb3798dce89ca171bc2c626f696b58
tfm-rubygem-katello-3.18.1.53-1.el7sat.src.rpm SHA-256: 8f37b31b6351a4204a860ed85c76992a848b48fa0ce57d553acd5601230f8f4c
x86_64
foreman-installer-2.3.1.22-1.el7sat.noarch.rpm SHA-256: 5107ac9b2c5fee5152b27eb233ddf5aa8392b445e5446e454341d2f44e162039
foreman-installer-katello-2.3.1.22-1.el7sat.noarch.rpm SHA-256: 2abdb52a8d6a68b805360e732cb966557b883fc3e5e4ea5f96836d7f9b1f1c68
pulp-rpm-admin-extensions-2.21.5.2-3.el7sat.noarch.rpm SHA-256: c23cbe48ae440340f4b681eb9d2a1b90bd84b9cd8bada63ccd5715596a50af21
pulp-rpm-plugins-2.21.5.2-3.el7sat.noarch.rpm SHA-256: 55513698094cfdb8294eed2a6d7cb8f933cb500d196ad612ada323c1ccc1cd5b
puppet-agent-6.26.0-1.el7sat.x86_64.rpm SHA-256: 6cb336f7438068db6128648f43bf826a8a3b096954f92537d4eaefe286304e06
puppetserver-6.18.0-1.el7sat.noarch.rpm SHA-256: 301cc35fd03649ac293d782020a71b3e5d158ddbedea043d3cc90754670587f3
python-pulp-integrity-2.21.5.2-3.el7sat.noarch.rpm SHA-256: f1983b648cbb38ae22449fae0e8ae5b2798b4e215e435b29d1cdfb4ca85421a7
python-pulp-rpm-common-2.21.5.2-3.el7sat.noarch.rpm SHA-256: 73f0d6cc14a125bc73860d66a26573fc24a679347acacd064b39c79768b2fe96
python3-pulp-2to3-migration-0.11.10-1.el7pc.noarch.rpm SHA-256: 849f66dcbedfbff5a493bcc01181bb093d4c60572728f4d3436edb97b2fd5158
python3-pulp-rpm-3.11.4-1.el7pc.noarch.rpm SHA-256: d891d85707930331322848df37c2b238ab5cb4ef5650ec1748a7b844bed6efab
satellite-6.9.9-1.el7sat.noarch.rpm SHA-256: 95887501baf307120f910ae500854dae6c84bc005e1b8e634f17d2b8143a6298
satellite-cli-6.9.9-1.el7sat.noarch.rpm SHA-256: fdf9a685d1e6bee51b36ba810550630f0e04dfeaed5a0059bf69418302950b07
satellite-common-6.9.9-1.el7sat.noarch.rpm SHA-256: 979371c4d6e83697a0349c755c95b20363f26131a25c32e45b665e58ee5a6d6d
satellite-debug-tools-6.9.9-1.el7sat.noarch.rpm SHA-256: 9c0ed34563bb6d3ef1bfc66949db8083d857ba4ffb9eea44be59698fb81dc3f4
tfm-rubygem-katello-3.18.1.53-1.el7sat.noarch.rpm SHA-256: 401e1c25f434d8f4f863a08be2153d089098ca8cc9a6e1e14232917deb421bfd

Red Hat Satellite Capsule 6.9

SRPM
foreman-installer-2.3.1.22-1.el7sat.src.rpm SHA-256: 2b654e1ed66b70fa45139d3f40f21e47109797cbafa957e4a4402ecc951e685a
pulp-rpm-2.21.5.2-3.el7sat.src.rpm SHA-256: d3c6624230816cace4821fb58a9d370ceb84b9600183af6a095d767733fe1816
puppet-agent-6.26.0-1.el7sat.src.rpm SHA-256: 4b54010a91ee8ffafe075b64c4003ad988d42c9316766dddd1fa73fcb4e25bfd
puppetserver-6.18.0-1.el7sat.src.rpm SHA-256: dcb912fb60c55732164584ac91ab58a4c55f09f197d4dba7e7cbf386aa6477f5
satellite-6.9.9-1.el7sat.src.rpm SHA-256: 6e561f6afad091bd98094723dedfb3f06efb3798dce89ca171bc2c626f696b58
x86_64
foreman-installer-2.3.1.22-1.el7sat.noarch.rpm SHA-256: 5107ac9b2c5fee5152b27eb233ddf5aa8392b445e5446e454341d2f44e162039
foreman-installer-katello-2.3.1.22-1.el7sat.noarch.rpm SHA-256: 2abdb52a8d6a68b805360e732cb966557b883fc3e5e4ea5f96836d7f9b1f1c68
pulp-rpm-admin-extensions-2.21.5.2-3.el7sat.noarch.rpm SHA-256: c23cbe48ae440340f4b681eb9d2a1b90bd84b9cd8bada63ccd5715596a50af21
pulp-rpm-plugins-2.21.5.2-3.el7sat.noarch.rpm SHA-256: 55513698094cfdb8294eed2a6d7cb8f933cb500d196ad612ada323c1ccc1cd5b
puppet-agent-6.26.0-1.el7sat.x86_64.rpm SHA-256: 6cb336f7438068db6128648f43bf826a8a3b096954f92537d4eaefe286304e06
puppetserver-6.18.0-1.el7sat.noarch.rpm SHA-256: 301cc35fd03649ac293d782020a71b3e5d158ddbedea043d3cc90754670587f3
python-pulp-integrity-2.21.5.2-3.el7sat.noarch.rpm SHA-256: f1983b648cbb38ae22449fae0e8ae5b2798b4e215e435b29d1cdfb4ca85421a7
python-pulp-rpm-common-2.21.5.2-3.el7sat.noarch.rpm SHA-256: 73f0d6cc14a125bc73860d66a26573fc24a679347acacd064b39c79768b2fe96
satellite-capsule-6.9.9-1.el7sat.noarch.rpm SHA-256: f62d10f86601ce75f34ad42b6b252546193f603096f3c6807f6ed4afe0beefd5
satellite-common-6.9.9-1.el7sat.noarch.rpm SHA-256: 979371c4d6e83697a0349c755c95b20363f26131a25c32e45b665e58ee5a6d6d
satellite-debug-tools-6.9.9-1.el7sat.noarch.rpm SHA-256: 9c0ed34563bb6d3ef1bfc66949db8083d857ba4ffb9eea44be59698fb81dc3f4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2022 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter