Headline
Red Hat Security Advisory 2022-8866-01
Red Hat Security Advisory 2022-8866-01 - An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: Red Hat OpenStack Platform 16.1.9 (python-XStatic-Angular) security update
Advisory ID: RHSA-2022:8866-01
Product: Red Hat OpenStack Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2022:8866
Issue date: 2022-12-07
CVE Names: CVE-2019-10768
====================================================================
- Summary:
An update for python-XStatic-Angular is now available for Red Hat OpenStack
Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
- Relevant releases/architectures:
Red Hat OpenStack Platform 16.1 - noarch
- Description:
Angular JavaScript library packaged for setuptools (easy_install) / pip.
Security Fix(es):
- Prototype pollution in merge function could result in code injection
(CVE-2019-10768)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.
- Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
- Bugs fixed (https://bugzilla.redhat.com/):
1813309 - CVE-2019-10768 AngularJS: Prototype pollution in merge function could result in code injection
- Package List:
Red Hat OpenStack Platform 16.1:
Source:
python-XStatic-Angular-1.5.8.0-13.el8ost.src.rpm
noarch:
XStatic-Angular-common-1.5.8.0-13.el8ost.noarch.rpm
python3-XStatic-Angular-1.5.8.0-13.el8ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
- References:
https://access.redhat.com/security/cve/CVE-2019-10768
https://access.redhat.com/security/updates/classification/#moderate
- Contact:
The Red Hat security contact is [email protected]. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBY5FpatzjgjWX9erEAQhl+w/5AfKkbI34bXXE7yfPixf+GvcfYai7s7Ku
3PBTymbKFdIla+c5zJfv5xux0YRYcqRt7tSlHHbybEEWxtrFXS9H8QSMW9q8h7QH
B32AsI3ooAKyrTTZqWDXyri77Z2WeNGXbyTc/2OTbNJANNZjAE5OmP2YtrInh0I9
y0Dds9U1gWJMFqO6mKamISJz6V+k7bmaaFeSHwZ59LfwIW5HD8OXM7yLsxgWyb4d
AxUSHugrRHgmjjoAwfylYlT+VPRgL9TvAa9/kuQgrGzq4Iy3bgtO3tkoJihweM/Y
BjxthGzwXBBA6MKHiwCqujm0GwtkfaBKMGNNJOVeY5BkqEYJOOyjN6y9kE/cYZ1K
zxvqotXYrhvx8RzQUNhaqpjreTa4AadLvGMdBEqMunAlXdUF9n3841lcfs0/daD3
I+N2YhPQHQ1ltusqp+50QIMf8EIAzptCQ4btMYhIRLdYYd7LwujcalqX5q4gC6is
lngsTlZ/HwQai5UJ//BozTTWegW5zeBEcqFdqsS7D4WQM/bn5o1eR6shBIzxsAhA
X3cpMk4vJ7E+nS+1wYVUEkmJZ26oZ4evCNYYpNu9FHtsUpN25IiM3qC5iw4GFIcZ
/zLmVLXAt/YN/4zDuu5I9fQD/MkaMoGnYppPkMXxja2ducJNuPnZiO0n2Qi2XbwB
qu4qTT4UppI=vX3U
-----END PGP SIGNATURE-----
–
RHSA-announce mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/rhsa-announce
Related news
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.
Red Hat Security Advisory 2023-0274-01 - Angular JavaScript library packaged for setuptools / pip.
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 17.0 (Wallaby). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
Red Hat Security Advisory 2022-8849-01 - An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.2.4 (Train).
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.2.4 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUserGroupProvider is not included in the default configuration. Command injection requires ShellUserGroupProvider to be one of the enabled User Group Providers in the Authorizers configuration. Command injection also requires an authenticated user with elevated privileges. Apache NiFi requires an authenticated user with authorization to modify access policies in order to execute the command. Apache NiFi Registry requires an authenticated user with authorization to read user groups in order to execute the command. The resolution removes command formatting based on user-provided arguments.
Couchbase Server before 7.1.0 has Incorrect Access Control.