RHSA-2020:4670: Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update

Published Nov 3, 2020
·
Updated

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments. The following packages have been upgraded to a later upstream version: ipa (4.8.7), softhsm (2.6.0), opendnssec (2.1.6). (BZ#1759888, BZ#1818765, BZ#1818877)Security Fix(es): js-jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251) bootstrap: XSS in the data-target attribute (CVE-2016-10735) bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040) bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042) bootstrap: XSS in the tooltip data-viewport attribute (CVE-2018-20676) bootstrap: XSS in the affix configuration target property (CVE-2018-20677) bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331) js-jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358) jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022) ipa: No password length restriction leads to denial of service (CVE-2020-1722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

Affected Software

161 affected componentsFixes available
redhat/bind-dyndb-ldap<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/custodia<0.6.0-3.module+el8.1.0+4098+f286395e
0.6.0-3.module+el8.1.0+4098+f286395e
redhat/ipa<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-healthcheck<0.4-6.module+el8.3.0+7710+e2408ce4
0.4-6.module+el8.3.0+7710+e2408ce4
redhat/opendnssec<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/python-jwcrypto<0.5.0-1.module+el8.1.0+4098+f286395e
0.5.0-1.module+el8.1.0+4098+f286395e
redhat/python-kdcproxy<0.4-5.module+el8.2.0+4691+a05b2456
0.4-5.module+el8.2.0+4691+a05b2456
redhat/python-qrcode<5.1-12.module+el8.1.0+4098+f286395e
5.1-12.module+el8.1.0+4098+f286395e
redhat/python-yubico<1.3.2-9.module+el8.1.0+4098+f286395e
1.3.2-9.module+el8.1.0+4098+f286395e
redhat/pyusb<1.0.0-9.module+el8.1.0+4098+f286395e
1.0.0-9.module+el8.1.0+4098+f286395e
redhat/slapi-nis<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/softhsm<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/ipa<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-healthcheck<0.4-6.module+el8.3.0+7711+c4441980
0.4-6.module+el8.3.0+7711+c4441980
redhat/python-jwcrypto<0.5.0-1.module+el8.1.0+4107+4a66eb87
0.5.0-1.module+el8.1.0+4107+4a66eb87
redhat/python-qrcode<5.1-12.module+el8.1.0+4107+4a66eb87
5.1-12.module+el8.1.0+4107+4a66eb87
redhat/python-yubico<1.3.2-9.module+el8.1.0+4107+4a66eb87
1.3.2-9.module+el8.1.0+4107+4a66eb87
redhat/pyusb<1.0.0-9.module+el8.1.0+4107+4a66eb87
1.0.0-9.module+el8.1.0+4107+4a66eb87
redhat/custodia<0.6.0-3.module+el8.1.0+4098+f286395e
0.6.0-3.module+el8.1.0+4098+f286395e
redhat/ipa-client-common<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-common<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-healthcheck<0.4-6.module+el8.3.0+7710+e2408ce4
0.4-6.module+el8.3.0+7710+e2408ce4
redhat/ipa-healthcheck-core<0.4-6.module+el8.3.0+7710+e2408ce4
0.4-6.module+el8.3.0+7710+e2408ce4
redhat/ipa-python-compat<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-selinux<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-common<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-dns<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/python3-custodia<0.6.0-3.module+el8.1.0+4098+f286395e
0.6.0-3.module+el8.1.0+4098+f286395e
redhat/python3-ipaclient<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/python3-ipalib<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/python3-ipaserver<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/python3-jwcrypto<0.5.0-1.module+el8.1.0+4098+f286395e
0.5.0-1.module+el8.1.0+4098+f286395e
redhat/python3-kdcproxy<0.4-5.module+el8.2.0+4691+a05b2456
0.4-5.module+el8.2.0+4691+a05b2456
redhat/python3-pyusb<1.0.0-9.module+el8.1.0+4098+f286395e
1.0.0-9.module+el8.1.0+4098+f286395e
redhat/python3-qrcode<5.1-12.module+el8.1.0+4098+f286395e
5.1-12.module+el8.1.0+4098+f286395e
redhat/python3-qrcode-core<5.1-12.module+el8.1.0+4098+f286395e
5.1-12.module+el8.1.0+4098+f286395e
redhat/python3-yubico<1.3.2-9.module+el8.1.0+4098+f286395e
1.3.2-9.module+el8.1.0+4098+f286395e
redhat/bind-dyndb-ldap<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/bind-dyndb-ldap-debuginfo<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/bind-dyndb-ldap-debugsource<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/ipa-client<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-epn<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-samba<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-debugsource<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-trust-ad<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-trust-ad-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/opendnssec<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/opendnssec-debuginfo<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/opendnssec-debugsource<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/slapi-nis<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/slapi-nis-debuginfo<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/slapi-nis-debugsource<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/softhsm<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/softhsm-debuginfo<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/softhsm-debugsource<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/softhsm-devel<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/ipa-client<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-common<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-debuginfo<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-epn<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-samba<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-common<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-debuginfo<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-debugsource<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-healthcheck-core<0.4-6.module+el8.3.0+7711+c4441980
0.4-6.module+el8.3.0+7711+c4441980
redhat/ipa-python-compat<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-selinux<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/python3-ipaclient<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/python3-ipalib<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/python3-jwcrypto<0.5.0-1.module+el8.1.0+4107+4a66eb87
0.5.0-1.module+el8.1.0+4107+4a66eb87
redhat/python3-pyusb<1.0.0-9.module+el8.1.0+4107+4a66eb87
1.0.0-9.module+el8.1.0+4107+4a66eb87
redhat/python3-qrcode<5.1-12.module+el8.1.0+4107+4a66eb87
5.1-12.module+el8.1.0+4107+4a66eb87
redhat/python3-qrcode-core<5.1-12.module+el8.1.0+4107+4a66eb87
5.1-12.module+el8.1.0+4107+4a66eb87
redhat/python3-yubico<1.3.2-9.module+el8.1.0+4107+4a66eb87
1.3.2-9.module+el8.1.0+4107+4a66eb87
redhat/bind-dyndb-ldap-debuginfo<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/bind-dyndb-ldap-debugsource<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/ipa-client<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-epn<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-samba<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-debugsource<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-trust-ad<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-trust-ad-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/opendnssec-debuginfo<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/opendnssec-debugsource<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/slapi-nis-debuginfo<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/slapi-nis-debugsource<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/softhsm-debuginfo<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/softhsm-debugsource<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/softhsm-devel<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/ipa-client<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-debuginfo<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-epn<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-samba<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-debuginfo<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-debugsource<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-debuginfo<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-epn<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-client-samba<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-debuginfo<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/ipa-debugsource<4.8.7-12.module+el8.3.0+8223+6212645f
4.8.7-12.module+el8.3.0+8223+6212645f
redhat/bind-dyndb-ldap<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/bind-dyndb-ldap-debuginfo<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/bind-dyndb-ldap-debugsource<11.3-1.module+el8.3.0+6993+104f8db0
11.3-1.module+el8.3.0+6993+104f8db0
redhat/ipa-client<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-epn<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-client-samba<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-debugsource<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-trust-ad<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/ipa-server-trust-ad-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a
4.8.7-12.module+el8.3.0+8222+c1bff54a
redhat/opendnssec<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/opendnssec-debuginfo<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/opendnssec-debugsource<2.1.6-2.module+el8.3.0+6580+328a3362
2.1.6-2.module+el8.3.0+6580+328a3362
redhat/slapi-nis<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/slapi-nis-debuginfo<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/slapi-nis-debugsource<0.56.5-4.module+el8.3.0+8222+c1bff54a
0.56.5-4.module+el8.3.0+8222+c1bff54a
redhat/softhsm<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/softhsm-debuginfo<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/softhsm-debugsource<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/softhsm-devel<2.6.0-3.module+el8.3.0+6909+fb33717d
2.6.0-3.module+el8.3.0+6909+fb33717d
redhat/ipa-client<4.8.7-12.module+el8.3.0+8223+6212645f.aa
4.8.7-12.module+el8.3.0+8223+6212645f.aa
redhat/ipa-client-debuginfo<4.8.7-12.module+el8.3.0+8223+6212645f.aa
4.8.7-12.module+el8.3.0+8223+6212645f.aa
redhat/ipa-client-epn<4.8.7-12.module+el8.3.0+8223+6212645f.aa
4.8.7-12.module+el8.3.0+8223+6212645f.aa
redhat/ipa-client-samba<4.8.7-12.module+el8.3.0+8223+6212645f.aa
4.8.7-12.module+el8.3.0+8223+6212645f.aa
redhat/ipa-debuginfo<4.8.7-12.module+el8.3.0+8223+6212645f.aa
4.8.7-12.module+el8.3.0+8223+6212645f.aa
redhat/ipa-debugsource<4.8.7-12.module+el8.3.0+8223+6212645f.aa
4.8.7-12.module+el8.3.0+8223+6212645f.aa
redhat/bind-dyndb-ldap<11.3-1.module+el8.3.0+6993+104f8db0.aa
11.3-1.module+el8.3.0+6993+104f8db0.aa
redhat/bind-dyndb-ldap-debuginfo<11.3-1.module+el8.3.0+6993+104f8db0.aa
11.3-1.module+el8.3.0+6993+104f8db0.aa
redhat/bind-dyndb-ldap-debugsource<11.3-1.module+el8.3.0+6993+104f8db0.aa
11.3-1.module+el8.3.0+6993+104f8db0.aa
redhat/ipa-client<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-client-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-client-epn<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-client-samba<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-debugsource<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-server<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-server-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-server-trust-ad<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/ipa-server-trust-ad-debuginfo<4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
redhat/opendnssec<2.1.6-2.module+el8.3.0+6580+328a3362.aa
2.1.6-2.module+el8.3.0+6580+328a3362.aa
redhat/opendnssec-debuginfo<2.1.6-2.module+el8.3.0+6580+328a3362.aa
2.1.6-2.module+el8.3.0+6580+328a3362.aa
redhat/opendnssec-debugsource<2.1.6-2.module+el8.3.0+6580+328a3362.aa
2.1.6-2.module+el8.3.0+6580+328a3362.aa
redhat/slapi-nis<0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
redhat/slapi-nis-debuginfo<0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
redhat/slapi-nis-debugsource<0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
redhat/softhsm<2.6.0-3.module+el8.3.0+6909+fb33717d.aa
2.6.0-3.module+el8.3.0+6909+fb33717d.aa
redhat/softhsm-debuginfo<2.6.0-3.module+el8.3.0+6909+fb33717d.aa
2.6.0-3.module+el8.3.0+6909+fb33717d.aa
redhat/softhsm-debugsource<2.6.0-3.module+el8.3.0+6909+fb33717d.aa
2.6.0-3.module+el8.3.0+6909+fb33717d.aa
redhat/softhsm-devel<2.6.0-3.module+el8.3.0+6909+fb33717d.aa
2.6.0-3.module+el8.3.0+6909+fb33717d.aa

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/ipa to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  2. Upgrade

    Upgrade redhat/ipa-healthcheck to a version that resolves this vulnerability.

    Fixed in 0.4-6.module+el8.3.0+7711+c4441980
  3. Upgrade

    Upgrade redhat/python-jwcrypto to a version that resolves this vulnerability.

    Fixed in 0.5.0-1.module+el8.1.0+4107+4a66eb87
  4. Upgrade

    Upgrade redhat/python-qrcode to a version that resolves this vulnerability.

    Fixed in 5.1-12.module+el8.1.0+4107+4a66eb87
  5. Upgrade

    Upgrade redhat/python-yubico to a version that resolves this vulnerability.

    Fixed in 1.3.2-9.module+el8.1.0+4107+4a66eb87
  6. Upgrade

    Upgrade redhat/pyusb to a version that resolves this vulnerability.

    Fixed in 1.0.0-9.module+el8.1.0+4107+4a66eb87
  7. Upgrade

    Upgrade redhat/bind-dyndb-ldap to a version that resolves this vulnerability.

    Fixed in 11.3-1.module+el8.3.0+6993+104f8db0
  8. Upgrade

    Upgrade redhat/custodia to a version that resolves this vulnerability.

    Fixed in 0.6.0-3.module+el8.1.0+4098+f286395e
  9. Upgrade

    Upgrade redhat/ipa to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  10. Upgrade

    Upgrade redhat/ipa-healthcheck to a version that resolves this vulnerability.

    Fixed in 0.4-6.module+el8.3.0+7710+e2408ce4
  11. Upgrade

    Upgrade redhat/opendnssec to a version that resolves this vulnerability.

    Fixed in 2.1.6-2.module+el8.3.0+6580+328a3362
  12. Upgrade

    Upgrade redhat/python-jwcrypto to a version that resolves this vulnerability.

    Fixed in 0.5.0-1.module+el8.1.0+4098+f286395e
  13. Upgrade

    Upgrade redhat/python-kdcproxy to a version that resolves this vulnerability.

    Fixed in 0.4-5.module+el8.2.0+4691+a05b2456
  14. Upgrade

    Upgrade redhat/python-qrcode to a version that resolves this vulnerability.

    Fixed in 5.1-12.module+el8.1.0+4098+f286395e
  15. Upgrade

    Upgrade redhat/python-yubico to a version that resolves this vulnerability.

    Fixed in 1.3.2-9.module+el8.1.0+4098+f286395e
  16. Upgrade

    Upgrade redhat/pyusb to a version that resolves this vulnerability.

    Fixed in 1.0.0-9.module+el8.1.0+4098+f286395e
  17. Upgrade

    Upgrade redhat/slapi-nis to a version that resolves this vulnerability.

    Fixed in 0.56.5-4.module+el8.3.0+8222+c1bff54a
  18. Upgrade

    Upgrade redhat/softhsm to a version that resolves this vulnerability.

    Fixed in 2.6.0-3.module+el8.3.0+6909+fb33717d
  19. Upgrade

    Upgrade redhat/ipa-client-common to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  20. Upgrade

    Upgrade redhat/ipa-common to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  21. Upgrade

    Upgrade redhat/ipa-healthcheck-core to a version that resolves this vulnerability.

    Fixed in 0.4-6.module+el8.3.0+7711+c4441980
  22. Upgrade

    Upgrade redhat/ipa-python-compat to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  23. Upgrade

    Upgrade redhat/ipa-selinux to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  24. Upgrade

    Upgrade redhat/python3-ipaclient to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  25. Upgrade

    Upgrade redhat/python3-ipalib to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  26. Upgrade

    Upgrade redhat/python3-jwcrypto to a version that resolves this vulnerability.

    Fixed in 0.5.0-1.module+el8.1.0+4107+4a66eb87
  27. Upgrade

    Upgrade redhat/python3-pyusb to a version that resolves this vulnerability.

    Fixed in 1.0.0-9.module+el8.1.0+4107+4a66eb87
  28. Upgrade

    Upgrade redhat/python3-qrcode to a version that resolves this vulnerability.

    Fixed in 5.1-12.module+el8.1.0+4107+4a66eb87
  29. Upgrade

    Upgrade redhat/python3-qrcode-core to a version that resolves this vulnerability.

    Fixed in 5.1-12.module+el8.1.0+4107+4a66eb87
  30. Upgrade

    Upgrade redhat/python3-yubico to a version that resolves this vulnerability.

    Fixed in 1.3.2-9.module+el8.1.0+4107+4a66eb87
  31. Upgrade

    Upgrade redhat/ipa-client-common to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  32. Upgrade

    Upgrade redhat/ipa-common to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  33. Upgrade

    Upgrade redhat/ipa-healthcheck-core to a version that resolves this vulnerability.

    Fixed in 0.4-6.module+el8.3.0+7710+e2408ce4
  34. Upgrade

    Upgrade redhat/ipa-python-compat to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  35. Upgrade

    Upgrade redhat/ipa-selinux to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  36. Upgrade

    Upgrade redhat/ipa-server-common to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  37. Upgrade

    Upgrade redhat/ipa-server-dns to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  38. Upgrade

    Upgrade redhat/python3-custodia to a version that resolves this vulnerability.

    Fixed in 0.6.0-3.module+el8.1.0+4098+f286395e
  39. Upgrade

    Upgrade redhat/python3-ipaclient to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  40. Upgrade

    Upgrade redhat/python3-ipalib to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  41. Upgrade

    Upgrade redhat/python3-ipaserver to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  42. Upgrade

    Upgrade redhat/python3-jwcrypto to a version that resolves this vulnerability.

    Fixed in 0.5.0-1.module+el8.1.0+4098+f286395e
  43. Upgrade

    Upgrade redhat/python3-kdcproxy to a version that resolves this vulnerability.

    Fixed in 0.4-5.module+el8.2.0+4691+a05b2456
  44. Upgrade

    Upgrade redhat/python3-pyusb to a version that resolves this vulnerability.

    Fixed in 1.0.0-9.module+el8.1.0+4098+f286395e
  45. Upgrade

    Upgrade redhat/python3-qrcode to a version that resolves this vulnerability.

    Fixed in 5.1-12.module+el8.1.0+4098+f286395e
  46. Upgrade

    Upgrade redhat/python3-qrcode-core to a version that resolves this vulnerability.

    Fixed in 5.1-12.module+el8.1.0+4098+f286395e
  47. Upgrade

    Upgrade redhat/python3-yubico to a version that resolves this vulnerability.

    Fixed in 1.3.2-9.module+el8.1.0+4098+f286395e
  48. Upgrade

    Upgrade redhat/ipa-client to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  49. Upgrade

    Upgrade redhat/ipa-client-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  50. Upgrade

    Upgrade redhat/ipa-client-epn to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  51. Upgrade

    Upgrade redhat/ipa-client-samba to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  52. Upgrade

    Upgrade redhat/ipa-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  53. Upgrade

    Upgrade redhat/ipa-debugsource to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f
  54. Upgrade

    Upgrade redhat/bind-dyndb-ldap-debuginfo to a version that resolves this vulnerability.

    Fixed in 11.3-1.module+el8.3.0+6993+104f8db0
  55. Upgrade

    Upgrade redhat/bind-dyndb-ldap-debugsource to a version that resolves this vulnerability.

    Fixed in 11.3-1.module+el8.3.0+6993+104f8db0
  56. Upgrade

    Upgrade redhat/ipa-client to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  57. Upgrade

    Upgrade redhat/ipa-client-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  58. Upgrade

    Upgrade redhat/ipa-client-epn to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  59. Upgrade

    Upgrade redhat/ipa-client-samba to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  60. Upgrade

    Upgrade redhat/ipa-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  61. Upgrade

    Upgrade redhat/ipa-debugsource to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  62. Upgrade

    Upgrade redhat/ipa-server to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  63. Upgrade

    Upgrade redhat/ipa-server-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  64. Upgrade

    Upgrade redhat/ipa-server-trust-ad to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  65. Upgrade

    Upgrade redhat/ipa-server-trust-ad-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a
  66. Upgrade

    Upgrade redhat/opendnssec-debuginfo to a version that resolves this vulnerability.

    Fixed in 2.1.6-2.module+el8.3.0+6580+328a3362
  67. Upgrade

    Upgrade redhat/opendnssec-debugsource to a version that resolves this vulnerability.

    Fixed in 2.1.6-2.module+el8.3.0+6580+328a3362
  68. Upgrade

    Upgrade redhat/slapi-nis-debuginfo to a version that resolves this vulnerability.

    Fixed in 0.56.5-4.module+el8.3.0+8222+c1bff54a
  69. Upgrade

    Upgrade redhat/slapi-nis-debugsource to a version that resolves this vulnerability.

    Fixed in 0.56.5-4.module+el8.3.0+8222+c1bff54a
  70. Upgrade

    Upgrade redhat/softhsm-debuginfo to a version that resolves this vulnerability.

    Fixed in 2.6.0-3.module+el8.3.0+6909+fb33717d
  71. Upgrade

    Upgrade redhat/softhsm-debugsource to a version that resolves this vulnerability.

    Fixed in 2.6.0-3.module+el8.3.0+6909+fb33717d
  72. Upgrade

    Upgrade redhat/softhsm-devel to a version that resolves this vulnerability.

    Fixed in 2.6.0-3.module+el8.3.0+6909+fb33717d
  73. Upgrade

    Upgrade redhat/bind-dyndb-ldap to a version that resolves this vulnerability.

    Fixed in 11.3-1.module+el8.3.0+6993+104f8db0.aa
  74. Upgrade

    Upgrade redhat/bind-dyndb-ldap-debuginfo to a version that resolves this vulnerability.

    Fixed in 11.3-1.module+el8.3.0+6993+104f8db0.aa
  75. Upgrade

    Upgrade redhat/bind-dyndb-ldap-debugsource to a version that resolves this vulnerability.

    Fixed in 11.3-1.module+el8.3.0+6993+104f8db0.aa
  76. Upgrade

    Upgrade redhat/ipa-client to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  77. Upgrade

    Upgrade redhat/ipa-client-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  78. Upgrade

    Upgrade redhat/ipa-client-epn to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  79. Upgrade

    Upgrade redhat/ipa-client-samba to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  80. Upgrade

    Upgrade redhat/ipa-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  81. Upgrade

    Upgrade redhat/ipa-debugsource to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  82. Upgrade

    Upgrade redhat/ipa-server to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  83. Upgrade

    Upgrade redhat/ipa-server-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  84. Upgrade

    Upgrade redhat/ipa-server-trust-ad to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  85. Upgrade

    Upgrade redhat/ipa-server-trust-ad-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8222+c1bff54a.aa
  86. Upgrade

    Upgrade redhat/opendnssec to a version that resolves this vulnerability.

    Fixed in 2.1.6-2.module+el8.3.0+6580+328a3362.aa
  87. Upgrade

    Upgrade redhat/opendnssec-debuginfo to a version that resolves this vulnerability.

    Fixed in 2.1.6-2.module+el8.3.0+6580+328a3362.aa
  88. Upgrade

    Upgrade redhat/opendnssec-debugsource to a version that resolves this vulnerability.

    Fixed in 2.1.6-2.module+el8.3.0+6580+328a3362.aa
  89. Upgrade

    Upgrade redhat/slapi-nis to a version that resolves this vulnerability.

    Fixed in 0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
  90. Upgrade

    Upgrade redhat/slapi-nis-debuginfo to a version that resolves this vulnerability.

    Fixed in 0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
  91. Upgrade

    Upgrade redhat/slapi-nis-debugsource to a version that resolves this vulnerability.

    Fixed in 0.56.5-4.module+el8.3.0+8222+c1bff54a.aa
  92. Upgrade

    Upgrade redhat/softhsm to a version that resolves this vulnerability.

    Fixed in 2.6.0-3.module+el8.3.0+6909+fb33717d.aa
  93. Upgrade

    Upgrade redhat/softhsm-debuginfo to a version that resolves this vulnerability.

    Fixed in 2.6.0-3.module+el8.3.0+6909+fb33717d.aa
  94. Upgrade

    Upgrade redhat/softhsm-debugsource to a version that resolves this vulnerability.

    Fixed in 2.6.0-3.module+el8.3.0+6909+fb33717d.aa
  95. Upgrade

    Upgrade redhat/softhsm-devel to a version that resolves this vulnerability.

    Fixed in 2.6.0-3.module+el8.3.0+6909+fb33717d.aa
  96. Upgrade

    Upgrade redhat/ipa-client to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f.aa
  97. Upgrade

    Upgrade redhat/ipa-client-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f.aa
  98. Upgrade

    Upgrade redhat/ipa-client-epn to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f.aa
  99. Upgrade

    Upgrade redhat/ipa-client-samba to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f.aa
  100. Upgrade

    Upgrade redhat/ipa-debuginfo to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f.aa
  101. Upgrade

    Upgrade redhat/ipa-debugsource to a version that resolves this vulnerability.

    Fixed in 4.8.7-12.module+el8.3.0+8223+6212645f.aa
  102. Upgrade

    Upgrade ipa to a version that resolves this vulnerability.

    Fixed in 4.8.7
  103. Upgrade

    Upgrade softhsm to a version that resolves this vulnerability.

    Fixed in 2.6.0
  104. Upgrade

    Upgrade opendnssec to a version that resolves this vulnerability.

    Fixed in 2.1.6

Event History

May 29, 2026
Advisory Published
via Red Hat·10:44 AM
Data Sourced
via Red Hat·10:44 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2020:4670?

The severity of RHSA-2020:4670 is classified as important.

2

How do I fix RHSA-2020:4670?

To fix RHSA-2020:4670, you should upgrade the affected packages to their latest versions as specified in the advisory.

3

Which packages are affected by RHSA-2020:4670?

The affected packages include ipa, softhsm, bind-dyndb-ldap, and several others related to Red Hat Identity Management.

4

Is there a workaround for RHSA-2020:4670?

There are no specific workarounds mentioned for RHSA-2020:4670; upgrading is recommended.

5

How can I check if I am affected by RHSA-2020:4670?

You can check the installed versions of the specified packages against the advisory to determine if you are affected by RHSA-2020:4670.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203