RHSA-2021:3473: Moderate: Red Hat Automation Platform 1.2.5 security and bugfixes update
Red Hat Ansible Automation Platform integrates Red Hat’s automation suiteconsisting of Red Hat Ansible Tower, Red Hat Ansible Engine, and use-casespecific capabilities for Microsoft Windows,network, security, and more,along with Software-as-a-Service (SaaS)-based capabilities and features fororganization-wide effectiveness.Security Fix(es): python-urllib3: Catastrophic backtracking in URL authority parser (CVE-2021-33503) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:This update fixes various bugs and adds enhancements. Documentation forthese changes is available from the Release Notes document linked to in theReferences section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/automation-hubto a version that resolves this vulnerability.Fixed in 4.2.6-1.el8 - Upgrade
Upgrade
redhat/python-galaxy-ngto a version that resolves this vulnerability.Fixed in 4.2.6-1.el8 - Upgrade
Upgrade
redhat/python-requeststo a version that resolves this vulnerability.Fixed in 2.25.1-1.el8 - Upgrade
Upgrade
redhat/python-urllib3to a version that resolves this vulnerability.Fixed in 1.26.5-1.el8 - Upgrade
Upgrade
redhat/python3-clickto a version that resolves this vulnerability.Fixed in 7.1.2-3.el8 - Upgrade
Upgrade
redhat/python3-galaxy-ngto a version that resolves this vulnerability.Fixed in 4.2.6-1.el8 - Upgrade
Upgrade
redhat/python3-gnupgto a version that resolves this vulnerability.Fixed in 0.4.6-3.el8 - Upgrade
Upgrade
redhat/python3-jinja2to a version that resolves this vulnerability.Fixed in 2.11.2-3.el8 - Upgrade
Upgrade
redhat/python3-markupsafeto a version that resolves this vulnerability.Fixed in 1.1.1-4.el8 - Upgrade
Upgrade
redhat/python3-markupsafe-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1-4.el8 - Upgrade
Upgrade
redhat/python3-markupsafe-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.1-4.el8 - Upgrade
Upgrade
redhat/python3-requeststo a version that resolves this vulnerability.Fixed in 2.25.1-1.el8 - Upgrade
Upgrade
redhat/python3-semantic-versionto a version that resolves this vulnerability.Fixed in 2.8.5-3.el8 - Upgrade
Upgrade
redhat/python3-urllib3to a version that resolves this vulnerability.Fixed in 1.26.5-1.el8 - Upgrade
Upgrade
redhat/automation-hubto a version that resolves this vulnerability.Fixed in 4.2.6-1.el7 - Upgrade
Upgrade
redhat/python-galaxy-ngto a version that resolves this vulnerability.Fixed in 4.2.6-1.el7 - Upgrade
Upgrade
redhat/python-requeststo a version that resolves this vulnerability.Fixed in 2.25.1-1.el7 - Upgrade
Upgrade
redhat/python-urllib3to a version that resolves this vulnerability.Fixed in 1.26.5-1.el7 - Upgrade
Upgrade
redhat/python3-clickto a version that resolves this vulnerability.Fixed in 7.1.2-3.el7 - Upgrade
Upgrade
redhat/python3-chardetto a version that resolves this vulnerability.Fixed in 3.0.4-3.el7 - Upgrade
Upgrade
redhat/python3-galaxy-ngto a version that resolves this vulnerability.Fixed in 4.2.6-1.el7 - Upgrade
Upgrade
redhat/python3-gnupgto a version that resolves this vulnerability.Fixed in 0.4.6-3.el7 - Upgrade
Upgrade
redhat/python3-jinja2to a version that resolves this vulnerability.Fixed in 2.11.2-3.el7 - Upgrade
Upgrade
redhat/python3-markupsafeto a version that resolves this vulnerability.Fixed in 1.1.1-4.el7 - Upgrade
Upgrade
redhat/python3-markupsafe-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1-4.el7 - Upgrade
Upgrade
redhat/python3-requeststo a version that resolves this vulnerability.Fixed in 2.25.1-1.el7 - Upgrade
Upgrade
redhat/python3-semantic-versionto a version that resolves this vulnerability.Fixed in 2.8.5-3.el7 - Upgrade
Upgrade
redhat/python3-urllib3to a version that resolves this vulnerability.Fixed in 1.26.5-1.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3473?
The severity of RHSA-2021:3473 is classified as moderate.
How do I fix RHSA-2021:3473?
To fix RHSA-2021:3473, users should update the affected packages to the specified remedies.
Which packages are affected by RHSA-2021:3473?
The affected packages include automation-hub, python-galaxy-ng, and python-requests among others.
What versions of the products are affected in RHSA-2021:3473?
Versions prior to 4.2.6-1.el8 for automation-hub and python-galaxy-ng are among those affected.
Is RHSA-2021:3473 related to any specific functionalities?
Yes, RHSA-2021:3473 involves components within the Red Hat Ansible Automation Platform and their interactions.