Headline
Red Hat Security Advisory 2023-0274-01
Red Hat Security Advisory 2023-0274-01 - Angular JavaScript library packaged for setuptools / pip.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: Red Hat OpenStack Platform 17.0 (python-XStatic-Angular) security update
Advisory ID: RHSA-2023:0274-01
Product: Red Hat OpenStack Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2023:0274
Issue date: 2023-01-25
CVE Names: CVE-2019-10768
====================================================================
- Summary:
An update for python-XStatic-Angular is now available for Red Hat OpenStack
Platform 17.0 (Wallaby).
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
- Relevant releases/architectures:
Red Hat OpenStack Platform 17.0 - noarch
- Description:
Angular JavaScript library packaged for setuptools (easy_install) / pip.
Security Fix(es):
- Prototype pollution in merge function could result in code injection
(CVE-2019-10768)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.
- Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
- Bugs fixed (https://bugzilla.redhat.com/):
1813309 - CVE-2019-10768 AngularJS: Prototype pollution in merge function could result in code injection
- Package List:
Red Hat OpenStack Platform 17.0:
Source:
python-XStatic-Angular-1.5.8.0-15.el9ost.src.rpm
noarch:
XStatic-Angular-common-1.5.8.0-15.el9ost.noarch.rpm
python3-XStatic-Angular-1.5.8.0-15.el9ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
- References:
https://access.redhat.com/security/cve/CVE-2019-10768
https://access.redhat.com/security/updates/classification/#moderate
- Contact:
The Red Hat security contact is [email protected]. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBY9FaJNzjgjWX9erEAQiO5g/+IxDa/ZzGCchT5ap2MfKHcNJT5nZxdalH
1feTMbJygrySaxWbTvuFzvQSTSgnYKRahZs+jApJ5kCeCpv1L7Wq8hkaey/zO+ur
LZhUzj86Tv2wvZMg0EBlCvBVbCGsTKrTa67yJ1a/bvvJIFqujv5K7fqD29xj4KW7
twynUmYaIzB5F5z35baug2aSAXRl+WOBoegXn/r1GycB/e3q6/EDxrx4h3TMPfEC
Ipa8kdhV2EwA/pdGxBurEb9TVHXBVtjyiCy2tPtJtZYwX/zlRDj7BR3wEYqQSpf+
vXkIe2Z1Om5oJM3EZnF/tBtaOH0a0mSeJXIfklNGXzutyhAJI43GIeG85AThNz2O
bIo9XI+ws0fLLGpnnug/cpOyxsS/H5YPjB5/KEvCDekCEZ58L/V/5WphgK/A7cyt
THchgvJ+o37ARG3Yi2Nn0/AePxPvDLs/NWm7qAoQA/SgajaVhm7ogjaA2v+p4LaB
5SuKnvG+B3lrmOHwu4io0neTccwxss6hAm0vLWvIjWsS2g6foviXTjq+h71vtnen
pwACnQh91X899rL9nqpVjxImqG0tllFCuhDCdAL+mbb41QeYWVbRWHyH5Goke9W3
8foDbRzIIHCQCcjWIOGY6A52L4dA+4Z8VoLIosKHj1OrFez2Zo3pq4Apf9i2lJkU
aLC02pHGTsM=+hEu
-----END PGP SIGNATURE-----
–
RHSA-announce mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/rhsa-announce
Related news
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 17.0 (Wallaby). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
Red Hat Security Advisory 2022-8849-01 - An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.2.4 (Train).
Red Hat Security Advisory 2022-8866-01 - An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2.
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.2.4 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUserGroupProvider is not included in the default configuration. Command injection requires ShellUserGroupProvider to be one of the enabled User Group Providers in the Authorizers configuration. Command injection also requires an authenticated user with elevated privileges. Apache NiFi requires an authenticated user with authorization to modify access policies in order to execute the command. Apache NiFi Registry requires an authenticated user with authorization to read user groups in order to execute the command. The resolution removes command formatting based on user-provided arguments.
Couchbase Server before 7.1.0 has Incorrect Access Control.