{"id":37584,"date":"2023-02-14T19:10:04","date_gmt":"2023-02-14T16:10:04","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170984\/RHSA-2023-0742-01.txt"},"modified":"2023-02-15T09:34:34","modified_gmt":"2023-02-15T06:04:34","slug":"red-hat-security-advisory-2023-0742-01-rhui","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2023-0742-01-rhui\/","title":{"rendered":"Red Hat Security Advisory 2023-0742-01 RHUI"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p>====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p>Synopsis: Low: RHUI 4.3.0 release &#8211; Security Fixes, Bug Fixes, and Enhancements Update<br \/>\nAdvisory ID: RHSA-2023:0742-01<br \/>\nProduct: Red Hat Update Infrastructure<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2023:0742<br \/>\nIssue date: 2023-02-13<br \/>\nCVE Names: CVE-2021-44420 CVE-2022-41323<br \/>\n====================================================================<br \/>\n1. Summary:<\/p>\n<p>An updated version of Red Hat Update Infrastructure (RHUI) is now<br \/>\navailable. RHUI 4.3 fixes a security bug, introduces multiple new features,<br \/>\nand upgrades underlying Pulp to a Long Term Support (LTS) version.<\/p>\n<p>2. Relevant releases\/architectures:<\/p>\n<p>RHUI 4 for RHEL 8 &#8211; noarch, x86_64<\/p>\n<p>3. Description:<\/p>\n<p>Red Hat Update Infrastructure (RHUI) offers a highly scalable, highly<br \/>\nredundant framework that enables you to manage repositories and content. It<br \/>\nalso enables cloud providers to deliver content and updates to Red Hat<br \/>\nEnterprise Linux (RHEL) instances.<\/p>\n<p>Security Fix(es):<br \/>\n* Django: Potential bypass of an upstream access control based on URL paths<br \/>\n(CVE-2021-44420)<\/p>\n<p>* Django: Potential denial-of-service vulnerability in internationalized<br \/>\nURLs (CVE-2022-41323)<\/p>\n<p>This RHUI update fixes the following bugs:<\/p>\n<p>* Previously, `rhui-manager` failed to create an Alternate Content Source<br \/>\npackage. With this update, the problem is now fixed and you can<br \/>\nsuccessfully create an Alternate Content Source package.<\/p>\n<p>* With this update, several parts of redundant code have been removed from<br \/>\nRHUI. Most notably, the unused `entitlement` argument in the custom<br \/>\nrepository creation has been removed. Additionally, the Atomic and OSTree<br \/>\nfunctions have been removed because these features have been deprecated in<br \/>\nRHUI 4.<\/p>\n<p>* Previously, CDS and HAProxy management used a variable called `port`.<br \/>\nHowever, this name is a reserved playbook keyword in Ansible. Consequently,<br \/>\nAnsible printed warnings about the use of this variable. With this update,<br \/>\nthe variable has been renamed to `remote_port` which prevents the warnings.<\/p>\n<p>* Previously, when the RHUA installation playbook failed, `rhui-installer`<br \/>\nexited with a status of 0, which normally indicates success. With this<br \/>\nupdate, the problem has been fixed, and `rhui-installer` exits with a<br \/>\nstatus of 1, indicating that the RHUA installation playbook has failed.<\/p>\n<p>* Previously, RHUI did not accept proxy server settings when adding<br \/>\ncontainer images. Consequently, RHUI was unable to synchronize container<br \/>\nimages if the proxy server configuration was required to access the<br \/>\ncontainer registries. With this update, RHUI now accepts proxy settings<br \/>\nwhen they are configured with the container images. As a result,<br \/>\nproxy-enabled RHUI environments can now synchronize container images.<\/p>\n<p>* With this update, the misaligned text on the repository workflow screen<br \/>\nin the rhui-manager text interface has been fixed.<\/p>\n<p>This RHUI update introduces the following enhancements:<\/p>\n<p>* This update introduces a newer version of Pulp, `3.21.0`. Among other<br \/>\nupstream bug fixes and enhancements, this version changes how Pulp manages<br \/>\nambiguous CDN repodata that contains a duplicate package<br \/>\nname-version-release string. Instead of failing, Pulp logs a warning and<br \/>\nallows the affected repository to be synchronized.(BZ#2134277)<\/p>\n<p>* A new `rhui-manager` command is now available, `rhui-manager<br \/>\n[&#8211;noninteractive] cds reinstall &#8211;all`. With this command, you can<br \/>\nreinstall all of your CDS nodes using a single command. Additionally, you<br \/>\ndo not need to specify any of the CDS host names.<\/p>\n<p>4. Solution:<\/p>\n<p>Before applying this update, make sure all previously released errata<br \/>\nrelevant to your system have been applied.<\/p>\n<p>For detailed instructions on how to apply this update, see:<br \/>\nhttps:\/\/access.redhat.com\/documentation\/en-us\/red_hat_update_infrastructure\/4\/html\/migrating_red_hat_update_infrastructure\/assembly_upgrading-red-hat-update-infrastructure_migrating-red-hat-update-infrastructure<\/p>\n<p>For other information, see the product documentation:<br \/>\nhttps:\/\/access.redhat.com\/documentation\/en-us\/red_hat_update_infrastructure\/4<\/p>\n<p>5. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p>2028178 &#8211; CVE-2021-44420 django: potential bypass of an upstream access control based on URL paths<br \/>\n2134277 &#8211; Using mirroring by default leads to errors with RH repos<br \/>\n2136130 &#8211; CVE-2022-41323 python-django: Potential denial-of-service vulnerability in internationalized URLs<\/p>\n<p>6. JIRA issues fixed (https:\/\/issues.jboss.org\/):<\/p>\n<p>RHUI-124 &#8211; Creating an alternate source configuration RPM is broken<br \/>\nRHUI-149 &#8211; Unused &#8220;entitlement&#8221; argument in custom repo creation<br \/>\nRHUI-169 &#8211; [WARNING]: Found variable using reserved name: port<br \/>\nRHUI-214 &#8211; Removal of atomic and OSTree client code<br \/>\nRHUI-296 &#8211; Update pulp to latest LTS version<br \/>\nRHUI-336 &#8211; rhui-installer exits with 0 even if the RHUA installation playbook fails<br \/>\nRHUI-341 &#8211; RFE: reinstall all CDS nodes in one simple step<br \/>\nRHUI-355 &#8211; Can&#8217;t sync an ARM64 container<br \/>\nRHUI-94 &#8211; slightly incorrect formatting on the wf screen<\/p>\n<p>7. Package List:<\/p>\n<p>RHUI 4 for RHEL 8:<\/p>\n<p>Source:<br \/>\ncreaterepo_c-0.20.1-1.0.1.el8ui.src.rpm<br \/>\nlibcomps-0.1.18-4.0.1.el8ui.src.rpm<br \/>\nlibsolv-0.7.22-4.0.1.el8ui.src.rpm<br \/>\npulpcore-selinux-1.3.2-1.0.1.el8ui.src.rpm<br \/>\npython-aiodns-3.0.0-4.1.1.el8ui.src.rpm<br \/>\npython-aiofiles-22.1.0-1.0.1.el8ui.src.rpm<br \/>\npython-aiohttp-3.8.1-3.0.1.el8ui.src.rpm<br \/>\npython-aiohttp-xmlrpc-1.5.0-2.0.1.el8ui.src.rpm<br \/>\npython-aioredis-2.0.1-2.0.1.el8ui.src.rpm<br \/>\npython-aiosignal-1.2.0-2.0.1.el8ui.src.rpm<br \/>\npython-asgiref-3.5.2-1.0.1.el8ui.src.rpm<br \/>\npython-async-timeout-4.0.2-2.0.1.el8ui.src.rpm<br \/>\npython-asyncio-throttle-1.0.2-4.1.1.el8ui.src.rpm<br \/>\npython-attrs-21.4.0-2.0.1.el8ui.src.rpm<br \/>\npython-backoff-2.1.2-1.0.1.el8ui.src.rpm<br \/>\npython-brotli-1.0.9-2.0.1.el8ui.src.rpm<br \/>\npython-cchardet-2.1.7-4.0.1.el8ui.src.rpm<br \/>\npython-charset-normalizer-2.1.1-1.0.1.el8ui.src.rpm<br \/>\npython-click-8.1.3-1.0.1.el8ui.src.rpm<br \/>\npython-defusedxml-0.7.1-3.0.1.el8ui.src.rpm<br \/>\npython-deprecated-1.2.13-1.0.1.el8ui.src.rpm<br \/>\npython-diff-match-patch-20200713-3.0.1.el8ui.src.rpm<br \/>\npython-django-3.2.16-1.0.1.el8ui.src.rpm<br \/>\npython-django-currentuser-0.5.3-5.0.1.el8ui.src.rpm<br \/>\npython-django-filter-22.1-2.0.1.el8ui.src.rpm<br \/>\npython-django-guid-3.3.0-1.0.1.el8ui.src.rpm<br \/>\npython-django-import-export-2.8.0-1.0.1.el8ui.src.rpm<br \/>\npython-django-lifecycle-1.0.0-1.0.1.el8ui.src.rpm<br \/>\npython-django-readonly-field-1.1.1-3.0.1.el8ui.src.rpm<br \/>\npython-djangorestframework-3.13.1-2.0.1.el8ui.src.rpm<br \/>\npython-djangorestframework-queryfields-1.0.0-6.1.1.el8ui.src.rpm<br \/>\npython-drf-access-policy-1.1.2-1.0.1.el8ui.src.rpm<br \/>\npython-drf-nested-routers-0.93.4-3.0.1.el8ui.src.rpm<br \/>\npython-drf-spectacular-0.23.1-1.0.1.el8ui.src.rpm<br \/>\npython-dynaconf-3.1.9-1.0.1.el8ui.src.rpm<br \/>\npython-ecdsa-0.14.1-2.0.1.el8ui.src.rpm<br \/>\npython-et-xmlfile-1.1.0-2.0.3.el8ui.src.rpm<br \/>\npython-frozenlist-1.3.0-2.0.1.el8ui.src.rpm<br \/>\npython-future-0.18.2-5.0.1.el8ui.src.rpm<br \/>\npython-gnupg-0.5.0-1.0.1.el8ui.src.rpm<br \/>\npython-gunicorn-20.1.0-7.1.1.el8ui.src.rpm<br \/>\npython-idna-ssl-1.1.0-6.1.1.el8ui.src.rpm<br \/>\npython-inflection-0.5.1-4.1.1.el8ui.src.rpm<br \/>\npython-jinja2-3.1.2-1.0.1.el8ui.src.rpm<br \/>\npython-jsonschema-4.9.1-1.0.1.el8ui.src.rpm<br \/>\npython-markuppy-1.14-3.0.1.el8ui.src.rpm<br \/>\npython-markupsafe-2.0.1-3.0.2.el8ui.src.rpm<br \/>\npython-multidict-6.0.2-2.0.1.el8ui.src.rpm<br \/>\npython-naya-1.1.1-3.0.1.el8ui.src.rpm<br \/>\npython-odfpy-1.4.1-6.0.1.el8ui.src.rpm<br \/>\npython-openpyxl-3.0.9-2.0.1.el8ui.src.rpm<br \/>\npython-packaging-21.3-1.0.1.el8ui.src.rpm<br \/>\npython-productmd-1.33-4.1.1.el8ui.src.rpm<br \/>\npython-protobuf-4.21.6-1.0.1.el8ui.src.rpm<br \/>\npython-psycopg2-2.9.3-2.0.1.el8ui.src.rpm<br \/>\npython-pulp-container-2.14.3-1.0.1.el8ui.src.rpm<br \/>\npython-pulp-container-client-2.14.1-1.4.el8ui.src.rpm<br \/>\npython-pulp-rpm-3.18.5-1.0.1.el8ui.src.rpm<br \/>\npython-pulp-rpm-client-3.18.5-1.2.el8ui.src.rpm<br \/>\npython-pulpcore-3.21.0-1.0.1.el8ui.src.rpm<br \/>\npython-pulpcore-client-3.21.0-1.0.1.el8ui.src.rpm<br \/>\npython-pycairo-1.20.1-5.1.1.el8ui.src.rpm<br \/>\npython-pycares-4.1.2-2.0.1.el8ui.src.rpm<br \/>\npython-pycryptodomex-3.14.1-2.0.1.el8ui.src.rpm<br \/>\npython-pygobject-3.40.1-4.0.1.el8ui.src.rpm<br \/>\npython-pygtrie-2.5.0-1.0.1.el8ui.src.rpm<br \/>\npython-pyjwkest-1.4.2-6.0.1.el8ui.src.rpm<br \/>\npython-pyjwt-2.5.0-2.0.1.el8ui.src.rpm<br \/>\npython-pyparsing-2.4.7-4.0.1.el8ui.src.rpm<br \/>\npython-pyrsistent-0.18.1-2.0.1.el8ui.src.rpm<br \/>\npython-pytz-2022.2.1-1.0.1.el8ui.src.rpm<br \/>\npython-redis-4.3.4-1.0.1.el8ui.src.rpm<br \/>\npython-sqlparse-0.4.2-4.1.1.el8ui.src.rpm<br \/>\npython-tablib-3.2.0-3.0.1.el8ui.src.rpm<br \/>\npython-types-cryptography-3.3.23-1.0.1.el8ui.src.rpm<br \/>\npython-typing-extensions-3.10.0.2-3.1.1.el8ui.src.rpm<br \/>\npython-uritemplate-4.1.1-3.1.1.el8ui.src.rpm<br \/>\npython-url-normalize-1.4.3-4.0.1.el8ui.src.rpm<br \/>\npython-urlman-2.0.1-1.0.1.el8ui.src.rpm<br \/>\npython-whitenoise-6.0.0-1.0.1.el8ui.src.rpm<br \/>\npython-wrapt-1.14.1-1.0.1.el8ui.src.rpm<br \/>\npython-xlrd-2.0.1-5.0.1.el8ui.src.rpm<br \/>\npython-xlwt-1.3.0-3.0.1.el8ui.src.rpm<br \/>\npython-yarl-1.7.2-4.1.1.el8ui.src.rpm<br \/>\nrhui-installer-4.3.0.4-1.el8ui.src.rpm<br \/>\nrhui-tools-4.3.0.8-1.el8ui.src.rpm<\/p>\n<p>noarch:<br \/>\npython3-gunicorn-20.1.0-7.1.1.el8ui.noarch.rpm<br \/>\npython3-pulp-container-client-2.14.1-1.4.el8ui.noarch.rpm<br \/>\npython3-pulp-rpm-client-3.18.5-1.2.el8ui.noarch.rpm<br \/>\npython3-pulpcore-client-3.21.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-aiodns-3.0.0-4.1.1.el8ui.noarch.rpm<br \/>\npython39-aiofiles-22.1.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-aiohttp-xmlrpc-1.5.0-2.0.1.el8ui.noarch.rpm<br \/>\npython39-aioredis-2.0.1-2.0.1.el8ui.noarch.rpm<br \/>\npython39-aiosignal-1.2.0-2.0.1.el8ui.noarch.rpm<br \/>\npython39-asgiref-3.5.2-1.0.1.el8ui.noarch.rpm<br \/>\npython39-async-timeout-4.0.2-2.0.1.el8ui.noarch.rpm<br \/>\npython39-asyncio-throttle-1.0.2-4.1.1.el8ui.noarch.rpm<br \/>\npython39-attrs-21.4.0-2.0.1.el8ui.noarch.rpm<br \/>\npython39-backoff-2.1.2-1.0.1.el8ui.noarch.rpm<br \/>\npython39-charset-normalizer-2.1.1-1.0.1.el8ui.noarch.rpm<br \/>\npython39-click-8.1.3-1.0.1.el8ui.noarch.rpm<br \/>\npython39-defusedxml-0.7.1-3.0.1.el8ui.noarch.rpm<br \/>\npython39-deprecated-1.2.13-1.0.1.el8ui.noarch.rpm<br \/>\npython39-diff-match-patch-20200713-3.0.1.el8ui.noarch.rpm<br \/>\npython39-django-3.2.16-1.0.1.el8ui.noarch.rpm<br \/>\npython39-django-currentuser-0.5.3-5.0.1.el8ui.noarch.rpm<br \/>\npython39-django-filter-22.1-2.0.1.el8ui.noarch.rpm<br \/>\npython39-django-guid-3.3.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-django-import-export-2.8.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-django-lifecycle-1.0.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-django-readonly-field-1.1.1-3.0.1.el8ui.noarch.rpm<br \/>\npython39-djangorestframework-3.13.1-2.0.1.el8ui.noarch.rpm<br \/>\npython39-djangorestframework-queryfields-1.0.0-6.1.1.el8ui.noarch.rpm<br \/>\npython39-drf-access-policy-1.1.2-1.0.1.el8ui.noarch.rpm<br \/>\npython39-drf-nested-routers-0.93.4-3.0.1.el8ui.noarch.rpm<br \/>\npython39-drf-spectacular-0.23.1-1.0.1.el8ui.noarch.rpm<br \/>\npython39-dynaconf-3.1.9-1.0.1.el8ui.noarch.rpm<br \/>\npython39-ecdsa-0.14.1-2.0.1.el8ui.noarch.rpm<br \/>\npython39-et-xmlfile-1.1.0-2.0.3.el8ui.noarch.rpm<br \/>\npython39-future-0.18.2-5.0.1.el8ui.noarch.rpm<br \/>\npython39-gnupg-0.5.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-gunicorn-20.1.0-7.1.1.el8ui.noarch.rpm<br \/>\npython39-idna-ssl-1.1.0-6.1.1.el8ui.noarch.rpm<br \/>\npython39-inflection-0.5.1-4.1.1.el8ui.noarch.rpm<br \/>\npython39-jinja2-3.1.2-1.0.1.el8ui.noarch.rpm<br \/>\npython39-jsonschema-4.9.1-1.0.1.el8ui.noarch.rpm<br \/>\npython39-markuppy-1.14-3.0.1.el8ui.noarch.rpm<br \/>\npython39-naya-1.1.1-3.0.1.el8ui.noarch.rpm<br \/>\npython39-odfpy-1.4.1-6.0.1.el8ui.noarch.rpm<br \/>\npython39-openpyxl-3.0.9-2.0.1.el8ui.noarch.rpm<br \/>\npython39-packaging-21.3-1.0.1.el8ui.noarch.rpm<br \/>\npython39-productmd-1.33-4.1.1.el8ui.noarch.rpm<br \/>\npython39-protobuf-4.21.6-1.0.1.el8ui.noarch.rpm<br \/>\npython39-pulp-container-2.14.3-1.0.1.el8ui.noarch.rpm<br \/>\npython39-pulp-rpm-3.18.5-1.0.1.el8ui.noarch.rpm<br \/>\npython39-pulpcore-3.21.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-pygtrie-2.5.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-pyjwkest-1.4.2-6.0.1.el8ui.noarch.rpm<br \/>\npython39-pyjwt-2.5.0-2.0.1.el8ui.noarch.rpm<br \/>\npython39-pyparsing-2.4.7-4.0.1.el8ui.noarch.rpm<br \/>\npython39-pytz-2022.2.1-1.0.1.el8ui.noarch.rpm<br \/>\npython39-redis-4.3.4-1.0.1.el8ui.noarch.rpm<br \/>\npython39-sqlparse-0.4.2-4.1.1.el8ui.noarch.rpm<br \/>\npython39-tablib-3.2.0-3.0.1.el8ui.noarch.rpm<br \/>\npython39-types-cryptography-3.3.23-1.0.1.el8ui.noarch.rpm<br \/>\npython39-typing-extensions-3.10.0.2-3.1.1.el8ui.noarch.rpm<br \/>\npython39-uritemplate-4.1.1-3.1.1.el8ui.noarch.rpm<br \/>\npython39-url-normalize-1.4.3-4.0.1.el8ui.noarch.rpm<br \/>\npython39-urlman-2.0.1-1.0.1.el8ui.noarch.rpm<br \/>\npython39-whitenoise-6.0.0-1.0.1.el8ui.noarch.rpm<br \/>\npython39-xlrd-2.0.1-5.0.1.el8ui.noarch.rpm<br \/>\npython39-xlwt-1.3.0-3.0.1.el8ui.noarch.rpm<br \/>\nrhui-installer-4.3.0.4-1.el8ui.noarch.rpm<br \/>\nrhui-tools-4.3.0.8-1.el8ui.noarch.rpm<br \/>\nrhui-tools-libs-4.3.0.8-1.el8ui.noarch.rpm<\/p>\n<p>x86_64:<br \/>\ncreaterepo_c-debuginfo-0.20.1-1.0.1.el8ui.x86_64.rpm<br \/>\ncreaterepo_c-debugsource-0.20.1-1.0.1.el8ui.x86_64.rpm<br \/>\ncreaterepo_c-libs-0.20.1-1.0.1.el8ui.x86_64.rpm<br \/>\ncreaterepo_c-libs-debuginfo-0.20.1-1.0.1.el8ui.x86_64.rpm<br \/>\nlibcomps-0.1.18-4.0.1.el8ui.x86_64.rpm<br \/>\nlibcomps-debuginfo-0.1.18-4.0.1.el8ui.x86_64.rpm<br \/>\nlibcomps-debugsource-0.1.18-4.0.1.el8ui.x86_64.rpm<br \/>\nlibsolv-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\nlibsolv-debuginfo-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\nlibsolv-debugsource-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\nlibsolv-demo-debuginfo-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\nlibsolv-tools-debuginfo-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\npulpcore-selinux-1.3.2-1.0.1.el8ui.x86_64.rpm<br \/>\npython-aiohttp-debugsource-3.8.1-3.0.1.el8ui.x86_64.rpm<br \/>\npython-brotli-debugsource-1.0.9-2.0.1.el8ui.x86_64.rpm<br \/>\npython-cchardet-debugsource-2.1.7-4.0.1.el8ui.x86_64.rpm<br \/>\npython-frozenlist-debugsource-1.3.0-2.0.1.el8ui.x86_64.rpm<br \/>\npython-markupsafe-debuginfo-2.0.1-3.0.2.el8ui.x86_64.rpm<br \/>\npython-markupsafe-debugsource-2.0.1-3.0.2.el8ui.x86_64.rpm<br \/>\npython-multidict-debugsource-6.0.2-2.0.1.el8ui.x86_64.rpm<br \/>\npython-psycopg2-debugsource-2.9.3-2.0.1.el8ui.x86_64.rpm<br \/>\npython-pycairo-debugsource-1.20.1-5.1.1.el8ui.x86_64.rpm<br \/>\npython-pycares-debugsource-4.1.2-2.0.1.el8ui.x86_64.rpm<br \/>\npython-pycryptodomex-debugsource-3.14.1-2.0.1.el8ui.x86_64.rpm<br \/>\npython-pygobject-debugsource-3.40.1-4.0.1.el8ui.x86_64.rpm<br \/>\npython-pyrsistent-debugsource-0.18.1-2.0.1.el8ui.x86_64.rpm<br \/>\npython-wrapt-debugsource-1.14.1-1.0.1.el8ui.x86_64.rpm<br \/>\npython-yarl-debugsource-1.7.2-4.1.1.el8ui.x86_64.rpm<br \/>\npython3-createrepo_c-0.20.1-1.0.1.el8ui.x86_64.rpm<br \/>\npython3-createrepo_c-debuginfo-0.20.1-1.0.1.el8ui.x86_64.rpm<br \/>\npython3-libcomps-0.1.18-4.0.1.el8ui.x86_64.rpm<br \/>\npython3-libcomps-debuginfo-0.1.18-4.0.1.el8ui.x86_64.rpm<br \/>\npython3-markupsafe-debuginfo-2.0.1-3.0.2.el8ui.x86_64.rpm<br \/>\npython3-solv-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\npython3-solv-debuginfo-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-aiohttp-3.8.1-3.0.1.el8ui.x86_64.rpm<br \/>\npython39-aiohttp-debuginfo-3.8.1-3.0.1.el8ui.x86_64.rpm<br \/>\npython39-brotli-1.0.9-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-brotli-debuginfo-1.0.9-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-cchardet-2.1.7-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-cchardet-debuginfo-2.1.7-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-createrepo_c-0.20.1-1.0.1.el8ui.x86_64.rpm<br \/>\npython39-createrepo_c-debuginfo-0.20.1-1.0.1.el8ui.x86_64.rpm<br \/>\npython39-frozenlist-1.3.0-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-frozenlist-debuginfo-1.3.0-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-libcomps-0.1.18-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-libcomps-debuginfo-0.1.18-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-markupsafe-2.0.1-3.0.2.el8ui.x86_64.rpm<br \/>\npython39-markupsafe-debuginfo-2.0.1-3.0.2.el8ui.x86_64.rpm<br \/>\npython39-multidict-6.0.2-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-multidict-debuginfo-6.0.2-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-psycopg2-2.9.3-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-psycopg2-debuginfo-2.9.3-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-pycairo-1.20.1-5.1.1.el8ui.x86_64.rpm<br \/>\npython39-pycairo-debuginfo-1.20.1-5.1.1.el8ui.x86_64.rpm<br \/>\npython39-pycares-4.1.2-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-pycares-debuginfo-4.1.2-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-pycryptodomex-3.14.1-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-pycryptodomex-debuginfo-3.14.1-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-pygobject-3.40.1-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-pygobject-debuginfo-3.40.1-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-pyrsistent-0.18.1-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-pyrsistent-debuginfo-0.18.1-2.0.1.el8ui.x86_64.rpm<br \/>\npython39-solv-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-solv-debuginfo-0.7.22-4.0.1.el8ui.x86_64.rpm<br \/>\npython39-wrapt-1.14.1-1.0.1.el8ui.x86_64.rpm<br \/>\npython39-wrapt-debuginfo-1.14.1-1.0.1.el8ui.x86_64.rpm<br \/>\npython39-yarl-1.7.2-4.1.1.el8ui.x86_64.rpm<br \/>\npython39-yarl-debuginfo-1.7.2-4.1.1.el8ui.x86_64.rpm<br \/>\nruby-solv-debuginfo-0.7.22-4.0.1.el8ui.x86_64.rpm<\/p>\n<p>These packages are GPG signed by Red Hat for security. Our key and<br \/>\ndetails on how to verify the signature are available from<br \/>\nhttps:\/\/access.redhat.com\/security\/team\/key\/<\/p>\n<p>8. References:<\/p>\n<p>https:\/\/access.redhat.com\/security\/cve\/CVE-2021-44420<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-41323<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#low<\/p>\n<p>9. Contact:<\/p>\n<p>The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p>Copyright 2023 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p>iQIVAwUBY+qBYNzjgjWX9erEAQjg\/A\/8DrdxSDYNezlo8qtNg\/4TxKmSRo13FONY<br \/>\nBEQccaAng84uVRHddCBSXdQJThk71DrjyJjJRybQA2KQFs74D0c426EmoYi4oTe3<br \/>\nxKmN23uN385SXOPwM04aKvo0q7zzhoxF8FkcAWBiqb6\/BRNGF8VLuIgWD8x2YTVZ<br \/>\namTrzLPSWShlotbRrWOwscYABdDKM9e3LTqDk9+1lFB4NdxO1RqO6eqq5WiH8hfL<br \/>\nyuFEdLbmgzBByneSQ+a9xbznH9cyoW4X7FJghcUdeHDXYfwlyOdDL8PMls5aMLm8<br \/>\n+4NayuPPnP94bMsw75yAtY6DUxz6d7paZZcSNW2UVNN9Q\/TXo1c\/DAFScpPcGaAn<br \/>\n3JYa5+xqzyM58XdNGI\/PutCSESxWgbpM4byM57eHMamC2y+ysCPYr5Gmwklalmk2<br \/>\nl31wLP6O\/BI37yCBvtJ23ID370RBlLIBAXWKS+ZvPFbUhKoXviV0a4bpawXSJerE<br \/>\nIoRO5xWC\/8CWVYI\/apUUpuyApPyr5i4Cqz8jBAKxcOQl24H2QTytvE5JXz\/mWo5Z<br \/>\nT52L9IHThn8dOgj4eDJ85bMuF84K2WthwtC5RByemLsK1uEv\/cyv\/ObkJs6vJwDc<br \/>\nVwI6Kqk1E4SB1n4LrK8tDrpsY1uY9zb\/YP3iy3plQ\/1a52Icuo93B6VBkzfeiOhG<br \/>\ntYN3nZ1I+EE\u0096H1<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: RHUI 4.3.0 release &#8211; Security Fixes, Bug Fixes, and Enhancements Update Advisory ID: RHSA-2023:0742-01 Product: Red Hat Update Infrastructure Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2023:0742 Issue date: 2023-02-13 CVE Names: CVE-2021-44420 CVE-2022-41323 ==================================================================== 1. Summary: An updated version of Red Hat Update Infrastructure (RHUI) is &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-37584","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/37584","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=37584"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/37584\/revisions"}],"predecessor-version":[{"id":37607,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/37584\/revisions\/37607"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=37584"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=37584"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=37584"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}