Red Hat Satellite 6.15 is vulnerable to cross-site scripting XSS due to installed package pycryptodomex version 3.14.1
Issue
-
The automatic removal of old packages does not occur after the upgrade of the Red Hat Satellite server necessitating manual intervention for their cleanup
-
The Satellite is vulnerable to a cross-site scripting (XSS) flaw due to an outdated version of the aioHTTP Python library. The version of
/usr/lib64/python3.9/pycryptodomexremains at3.14.1instead of the3.19.1in Satellite version 6.15
Environment
- Red Hat Satellite 6
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.