Headline
Red Hat Security Advisory 2022-8851-01
Red Hat Security Advisory 2022-8851-01 - An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.2.4 (Train) for Red Hat Enterprise Linux (RHEL) 8.4. Issues addressed include cross site scripting and improper neutralization vulnerabilities.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Low: Red Hat OpenStack Platform 16.2.4 (rabbitmq-server) security update
Advisory ID: RHSA-2022:8851-01
Product: Red Hat OpenStack Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2022:8851
Issue date: 2022-12-07
CVE Names: CVE-2021-32718 CVE-2021-32719
====================================================================
- Summary:
An update for rabbitmq-server is now available for Red Hat OpenStack
Platform 16.2.4 (Train) for Red Hat Enterprise Linux (RHEL) 8.4.
Red Hat Product Security has rated this update as having a security impact
of Low. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
- Relevant releases/architectures:
Red Hat OpenStack Platform 16.2 - ppc64le, x86_64
- Description:
RabbitMQ is an implementation of AMQP, the emerging standard for high
performance enterprise messaging. The RabbitMQ server is a robust and
scalable implementation of an AMQP broker. # We want to install into
/usr/lib, even on 64-bit platforms
Security Fix(es):
improper neutralization of script-related HTML tags in a web page (basic
XSS) in management UI (CVE-2021-32718)improper neutralization of script-related HTML tags in a web page (basic
XSS) in federation management plugin (CVE-2021-32719)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.
- Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
- Bugs fixed (https://bugzilla.redhat.com/):
1977002 - CVE-2021-32718 rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in management UI
1977008 - CVE-2021-32719 rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in federation management plugin
- Package List:
Red Hat OpenStack Platform 16.2:
Source:
rabbitmq-server-3.8.16-3.el8ost.src.rpm
ppc64le:
rabbitmq-server-3.8.16-3.el8ost.ppc64le.rpm
x86_64:
rabbitmq-server-3.8.16-3.el8ost.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
- References:
https://access.redhat.com/security/cve/CVE-2021-32718
https://access.redhat.com/security/cve/CVE-2021-32719
https://access.redhat.com/security/updates/classification/#low
- Contact:
The Red Hat security contact is [email protected]. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBY5Fpc9zjgjWX9erEAQh6TA//SBk6DFowl0p6bJNt+PFGZPB8ZIrl0HPI
azUxSF3o/b29uqTe1XNVS83lN+2dsTUp0rERs34Kd7kbkOvqHyGj9TDjnvyVt1QH
HD6yXG9iCit7cYNCYNDwea+Wt6yczY0BrmednQfukXfnV8DjNZ2btwQqsASdNrD6
fcuYlQB3eQVVD/L1GCjmCP+nHbwD7A5egqlxXNJlw0WhtSvIa7YdQ4T+MUN5w30I
kuJWc3wPEKj7+NbKlyZ2ErCz6DrMm5BDjAHhOviXnY2S0Ya9pwzIDrCUk3KDxNtU
SKO44qVkZOQkevGHtyUfHbXM1Zm41BWHg/caQuQMO4gIw9Aw02MMOoOpJwXLRURn
cMb0pOtuvTgIyfpjGT8xJb51cWb71Xw9Za+VUQNMRS+Xp00yTR2lH74ILKhv1/fj
8SdiGYmwJ3bYBBHvM+mCnhDiH6w7s9E9JjTsTLqZYdtx/4AGUULowC1q64h+TfEs
cEdnv0kV8sNVMf71Iz0d2yzDj5DE7ZHhXEUy0CWop/ja/i/vr+B0zGb1T8nEZml4
xYofh90zY4tHdH3vquUBTQg1BgEiJXXLo0vVKC6IzfS84kOpogJrVdsIsWURB2Xq
bd4AwKt9lCdQVrAWfnynQEyRJ/MIaEieFK7xzCEzORb8DtTjYTONn8UsuHx9PeYB
6ofOgrgazRA=/s43
-----END PGP SIGNATURE-----
–
RHSA-announce mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/rhsa-announce
Related news
Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows a remote attacker to execute arbitrary code via a crafted script upload.
Red Hat Security Advisory 2022-8867-01 - An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Issues addressed include cross site scripting and improper neutralization vulnerabilities.
An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2021-32718: rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in management UI
An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.2.4 (Train) for Red Hat Enterprise Linux (RHEL) 8.4. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2021-32718: rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in management UI * CVE-2021-32719: rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in federation management plugin
An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.2.4 (Train) for Red Hat Enterprise Linux (RHEL) 8.4. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2021-32718: rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in management UI * CVE-2021-32719: rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in federation management plugin