8.21.5. RHSA-2024:3781 - 安全公告 - 2024 年 6 月 10 日


RHSA-2024:3781

8.21.5.1. General

  • automation-controller-cli 软件包添加到 ansible-developer RPM 存储库(AAP-23368)中。

在这个版本中,解决了以下 CVE:

  • CVE-2023-45288 - 无限数量的 CONTINUATION 帧会导致拒绝服务(DoS)。

    • 软件包已更新: receptor: golang: net/http, x/net/http2.
  • CVE-2023-45290 - memory exhaustion in Request.ParseMultipartForm.

    • 软件包已更新: receptor: golang: net/http.
  • CVE-2023-49083 - 加载 PKCS7 证书时 null-pointer dereference。

    • 软件包已更新: python3-cryptographypython39-cryptography.
  • CVE-2023-50447 - 使用 environment 参数执行任意代码。

    • 软件包已更新: python3-pillowpython39-pillow.
  • CVE-2024-1135 - HTTP 请求交换,因为未验证 Transfer-Encoding 标头。

    • 软件包已更新: python3-gunicornpython39-gunicorn
  • CVE-2024-21503- 正则表达式拒绝 字符串.py 文件中的 lines_with_leading_tabs_expanded () 函数的 lines_with_tabs_expanded () 函数。

    • 软件包已更新: python3-blackpython39-black.
  • CVE-2024-24783 - 验证带有未知公钥算法的证书上的 panics。

    • 软件包已更新: receptor: golang: crypto/x509.
  • 当使用不匹配的证书和私钥以及 hmac_hash 覆盖调用时,CVE-2024-26130 - NULL pointer dereference with pkcs12.serialize_key_and_certificates

    • 软件包已更新: python3-cryptographypython39-cryptography.
  • CVE-2024-27306 - 在用于静态文件处理的索引页面上的跨站点脚本(XSS)

    • 软件包已更新: python3-aiohttppython39-aiohttp
  • CVE-2024-27351- django.utils.text.Truncator.words () 中的潜在的 ReDoS .

    • 软件包已更新: automation-controller: Django.
  • CVE-2024-28219- 缓冲区溢出 _imagingcms.c.

    • 软件包已更新: python3-pillowpython39-pillow.
  • CVE-2024-28849 - 可能的凭证泄漏。

    • 软件包已更新: python3-galaxy-ng: follow-redirects,python39-galaxy-ng: follow-redirects, 和 automation-hub: follow-redirects.
  • CVE-2024-30251 - 当尝试解析不正确的 POST 请求时,DoS。

    • 软件包已更新: python3-aiohttp,python39-aiohttp, 和 automation-controller: aiohttp.
  • CVE-2024-3287 9- incorrect processing of case sensitivity in social-auth-app-django.

    • 软件包已更新: python3-social-auth-app-djangopython39-social-auth-app-django
  • CVE-2024-340 64- xmlattr 过滤器接受包含非属性字符的密钥。

    • 软件包已更新: python3-jinja2python39-jinja2
  • CVE-2024-35195 - 对同一主机的额外请求忽略证书验证。

    • 软件包已更新: python3-requestspython39-requests.
  • CVE-2024-3651 - 通过对 idna.encode () 的特殊设计的输入来利用资源消耗的潜在 DoS。

    • 软件包已更新: python3-idnapython39-idna
  • CVE-2024-3772 - ReDoS 带有精心设计的电子邮件字符串。

    • 软件包已更新: python3-pydantic,python39-pydantic, 和 automation-controller: python-pydantic.
  • CVE-2024-4340 - 解析大量嵌套列表会导致 DoS。

    • 软件包已更新: python3-sqlparsepython39-sqlparse
  • 当使用 pip 安装时,CVE-2023 -5752- Mercurial 配置注入存储库修订中的 配置注入。

    • 软件包已更新: automation-controller: pip.
Red Hat logoGithubredditYoutubeTwitter

学习

尝试、购买和销售

社区

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

关于红帽文档

Legal Notice

Theme

© 2026 Red Hat
返回顶部