Headline
Red Hat Security Advisory 2022-8849-01
Red Hat Security Advisory 2022-8849-01 - An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.2.4 (Train).
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: Red Hat OpenStack Platform 16.2.4 (python-XStatic-Angular) security update
Advisory ID: RHSA-2022:8849-01
Product: Red Hat OpenStack Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2022:8849
Issue date: 2022-12-07
CVE Names: CVE-2019-10768
====================================================================
- Summary:
An update for python-XStatic-Angular is now available for Red Hat OpenStack
Platform 16.2.4 (Train).
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
- Relevant releases/architectures:
Red Hat OpenStack Platform 16.2 - noarch
- Description:
Angular JavaScript library packaged for setuptools (easy_install) / pip.
Security Fix(es):
- Prototype pollution in merge function could result in code injection
(CVE-2019-10768)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.
- Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
- Bugs fixed (https://bugzilla.redhat.com/):
1813309 - CVE-2019-10768 AngularJS: Prototype pollution in merge function could result in code injection
- Package List:
Red Hat OpenStack Platform 16.2:
Source:
python-XStatic-Angular-1.5.8.0-13.el8ost.src.rpm
noarch:
XStatic-Angular-common-1.5.8.0-13.el8ost.noarch.rpm
python3-XStatic-Angular-1.5.8.0-13.el8ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
- References:
https://access.redhat.com/security/cve/CVE-2019-10768
https://access.redhat.com/security/updates/classification/#moderate
- Contact:
The Red Hat security contact is [email protected]. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBY5FpVdzjgjWX9erEAQhHKw//R+N/9lZBpBGHZo/FYTh/4l1u1L/m07bG
wW/+z3D185zL4LZQQS//K2WpzMgZEgEV8GlvVJ8FG0Olw8urrZzervxI8r72xApD
9Wx0TAFh8Sgf/t5qJvvt022jrXlOE9/+Y9EjYxoSWkbVmFUKUodeL4Me1H0oTpRY
OzKtkRg/E7TNwQEllFpJgyFICUoUr21EyhreE7gSRga/2MqVNDwsWOiPhcxNZqB1
Cz/yssJftzrUL3dbi9BbOsIelsMDAS9woSkZD7uS4xXdNmwcFxbxVazaX6L/XzuR
HTETjmy2xxy/oO6eFj8/Ym/ZvjnCxkesaSigvUMFV5CMNqMEMWO4xZKdDXTuFY4X
4iZFc4FTQKwRqd8bCosFEqUcinw3NmuByIU3MnPhSbaY0La+FsqbZ614K+wBxxlC
NlBfUV5WkgYWP/Jd++I4vOWOLoxfabplRlvN84lperErtieX+YAMKZWgQpP0rEXd
bfC9O3/N1sfA3wg4ZFf8KQPFPR9EAEaI3WPyqmrx7QX6wt+nO1n6HueiQ8G2hkfT
RAkBCoPikgNk7mLBxFdicMX8mvawKoDGam3SByk8NLK6nS4TDogfmTKOhioaRL18
e3JvzZ0Qyr3xHdnXwyOHpbZEL2lOCcgAOQIWxDbUj7EZul9Vu5jpFHtqYmPHmOEn
YO5E1kZUxbE=KRoQ
-----END PGP SIGNATURE-----
–
RHSA-announce mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/rhsa-announce
Related news
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript code can be executed within the session context of the authenticated user. Upgrading to Apache NiFi 1.24.0 or 2.0.0-M1 is the recommended mitigation.
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.
Red Hat Security Advisory 2023-0274-01 - Angular JavaScript library packaged for setuptools / pip.
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 17.0 (Wallaby). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
Red Hat Security Advisory 2022-8866-01 - An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2.
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
An update for python-XStatic-Angular is now available for Red Hat OpenStack Platform 16.2.4 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2019-10768: AngularJS: Prototype pollution in merge function could result in code injection
The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUserGroupProvider is not included in the default configuration. Command injection requires ShellUserGroupProvider to be one of the enabled User Group Providers in the Authorizers configuration. Command injection also requires an authenticated user with elevated privileges. Apache NiFi requires an authenticated user with authorization to modify access policies in order to execute the command. Apache NiFi Registry requires an authenticated user with authorization to read user groups in order to execute the command. The resolution removes command formatting based on user-provided arguments.
Couchbase Server before 7.1.0 has Incorrect Access Control.