fence-agents-4.10.0-62.el9_4.3
エラータID: AXSA:2024-8287:07
リリース日:
2024/06/17 Monday - 15:47
題名:
fence-agents-4.10.0-62.el9_4.3
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- Jinja2 の xmlattr フィルターには、HTML テンプレート内に
'/'、'>'、および '=' などの非属性文字を挿入できてしまう問題が
あるため、リモートの攻撃者により、細工されたテンプレート
を介して、クロスサイトスクリプティング攻撃を可能とする
脆弱性が存在します。(CVE-2024-34064)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2024-34064
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.
追加情報:
N/A
ダウンロード:
SRPMS
- fence-agents-4.10.0-62.el9_4.3.src.rpm
MD5: 3c77649d13b4c3b1c792564406523a82
SHA-256: 19c1d4580acb2e743a12cf93df117934441ab94cd870328ff6e4aa647ee05201
Size: 68.85 MB
Asianux Server 9 for x86_64
- fence-agents-aliyun-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 28779c4c29ece11e688749195dfc4fe1
SHA-256: 87b8566daa0299cdf6b8fef1ae8494c2271af48a5fcc8d14eda0a69e6fcb11cf
Size: 15.10 kB - fence-agents-all-4.10.0-62.el9_4.3.x86_64.rpm
MD5: f79cfa1f2014f6e24ad579032ff42e93
SHA-256: d0ba56aa411ae1d112d7275761c828bed873907016710878019a9f5c5d57727e
Size: 11.95 kB - fence-agents-amt-ws-4.10.0-62.el9_4.3.noarch.rpm
MD5: 00551643984821bdd56ed349af93e7ba
SHA-256: 7d6bf8da76aa861a090fdae94732d41313257656b46742472dccf63afc05735e
Size: 15.97 kB - fence-agents-apc-4.10.0-62.el9_4.3.noarch.rpm
MD5: b4c1e517be2b99bdbc873b77d5928c14
SHA-256: dc0e5dd06db84984b41c04641d34880e5d024c02d9dc3ef7b957f4745f828833
Size: 16.09 kB - fence-agents-apc-snmp-4.10.0-62.el9_4.3.noarch.rpm
MD5: 406ae998cc3be04edeb0d97624be0db1
SHA-256: 91115fdb96c331c404032a674e5a7e933f77e7d9eeca0e87544bc87df7cf4856
Size: 18.45 kB - fence-agents-aws-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 8326d63320d4fb4ce157fd465bb87466
SHA-256: a68673670daed94f506190a5bcd24c8c105de4121c4d73d12a6d2d9d1d362b66
Size: 16.13 kB - fence-agents-azure-arm-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 77c4c03f6d8a8dd235ed175fe6478abf
SHA-256: 1bc6aec29a51f0d1b2155e5b23e1e747d0f520a2ff960d92e873112b47a70004
Size: 25.50 kB - fence-agents-bladecenter-4.10.0-62.el9_4.3.noarch.rpm
MD5: 1260d4f11626140e809a02312a82dbd8
SHA-256: 7691ec948b2ee6a8d89dba111cb69221176ea989a2875ad1ebaf92f356045fa9
Size: 15.13 kB - fence-agents-brocade-4.10.0-62.el9_4.3.noarch.rpm
MD5: bea3949f1078b385d004d86d6eeb0d05
SHA-256: 0b4f221354db32fb9b239eb38890be6b46f7a195cffd8bdecbf928c5a23f8727
Size: 15.22 kB - fence-agents-cisco-mds-4.10.0-62.el9_4.3.noarch.rpm
MD5: 9916bdf22dbbf5660396b4d50b65b958
SHA-256: cd2bcbc3011c7c62370a3eecb533e334c38a4b84d10cc7133c5e91fca2f51b54
Size: 15.07 kB - fence-agents-cisco-ucs-4.10.0-62.el9_4.3.noarch.rpm
MD5: 2034a9e6b760bffca6be3b4076fa68e0
SHA-256: 9ffa83b80352f4aa03cb6f3f0ead7bed83fddbea357cb8d29afccaabc2a65b96
Size: 15.76 kB - fence-agents-common-4.10.0-62.el9_4.3.noarch.rpm
MD5: 90ca8f7f298618fced85eb070526d175
SHA-256: a6e164cf46e361195d976591e58d6d8ff2f85a3edeec3687dae3ecc2557cfc89
Size: 425.61 kB - fence-agents-compute-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 06e7726038882f59cfad330ca333b8ad
SHA-256: 2ba32f253fcf53258fa7448e47cfaa0030219286bfc8edcebf9338e05e5d608b
Size: 22.20 kB - fence-agents-drac5-4.10.0-62.el9_4.3.noarch.rpm
MD5: a19c906d451b96b80716fa3ff1853098
SHA-256: 945e4a641199de29bed4b9677ff82f9d35a4c693707131e08ac35ae71098051b
Size: 15.74 kB - fence-agents-eaton-snmp-4.10.0-62.el9_4.3.noarch.rpm
MD5: 3910717154e73404d8b41d96f3bd5412
SHA-256: 536d11507333c763d360d6e5bb131fabb182278fac504d484faf7b3db5ae38e8
Size: 16.24 kB - fence-agents-emerson-4.10.0-62.el9_4.3.noarch.rpm
MD5: 5240b7ae84a6262c4de5fe3fc27d41f0
SHA-256: 17cdb31dea411388a4edfe673446b3f08763027c359c1d9bb2f25c340efa73b8
Size: 14.72 kB - fence-agents-eps-4.10.0-62.el9_4.3.noarch.rpm
MD5: 476742da55ca33ba87bfdd6263ff8438
SHA-256: b0d53339b268cefc5baaf2f5778dd94d0edce21ef602a90ea5f5281c3eb59b9e
Size: 17.54 kB - fence-agents-gce-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 76ab1a702da2ac76c54b387ec23b3abf
SHA-256: 24d5e646312f686a46191b49cd1d294c079adad7fa0320fb34993c1dd9ef71dc
Size: 20.10 kB - fence-agents-heuristics-ping-4.10.0-62.el9_4.3.noarch.rpm
MD5: 550a7f2d45bf8d69f7ae1710c079ab78
SHA-256: 58906376ef6278d6c48edfdd424636ba8ef3bcca38aad1852dded5f4fe8e915b
Size: 15.60 kB - fence-agents-hpblade-4.10.0-62.el9_4.3.noarch.rpm
MD5: a1c41342d3c76abfc17c8115311532b6
SHA-256: c17bb9528416cd1189db91cb5e82e30f5bc8a1e6712de49ea7fe9db0e35a70d6
Size: 15.30 kB - fence-agents-ibmblade-4.10.0-62.el9_4.3.noarch.rpm
MD5: 193116637da7a4495431850ab8376ff4
SHA-256: 79c01d3ef7945b76991cd42e5d4093abaf82674ff7cb5bfc9f460a0173a20d79
Size: 14.84 kB - fence-agents-ibm-powervs-4.10.0-62.el9_4.3.noarch.rpm
MD5: 7ece4efe03fde2d43cf0ceac207432fe
SHA-256: df92bce3e8de0ba94a5a4e45123fcbd557d2db22ababce2a9a0d007e70674ccd
Size: 15.88 kB - fence-agents-ibm-vpc-4.10.0-62.el9_4.3.noarch.rpm
MD5: 16c1b13a6b626695bfd688fa6d95b1d6
SHA-256: 1c813cedd3ec7b5e8865e72c8aae08531417aa2921d0f9dc42c09b5d4189f722
Size: 16.35 kB - fence-agents-ifmib-4.10.0-62.el9_4.3.noarch.rpm
MD5: 09d4597f86887af64c3eccb44bf3a195
SHA-256: fc0f2c73a2a1728cead9b5eb9ed4d3fb1143ecf91464dc48427cf9d4d4a88597
Size: 15.41 kB - fence-agents-ilo2-4.10.0-62.el9_4.3.noarch.rpm
MD5: 4492374a9d32545071e83a91a7db0e26
SHA-256: 3d825285fbc7608542bd0152ca2955773d054a07ed74ed9cd57506622213e5ed
Size: 17.37 kB - fence-agents-ilo-moonshot-4.10.0-62.el9_4.3.noarch.rpm
MD5: 7701af57169a8fbe45b6dade815276ce
SHA-256: de307911a26d8714852067eb3c17fa982c6b234ea501e97cb1ef4a6dd00f6381
Size: 14.62 kB - fence-agents-ilo-mp-4.10.0-62.el9_4.3.noarch.rpm
MD5: 7de542de3fba2ee94101b6b0fba1844a
SHA-256: d7640284d2c5f40337ba8d82706ddaf26d71f6e1d9737521462ac7e25a93e0c4
Size: 14.37 kB - fence-agents-ilo-ssh-4.10.0-62.el9_4.3.noarch.rpm
MD5: d22d0587a2e8e9a7bd0230cbbab96105
SHA-256: cd765e2219f0fc4d8f158c5042bde8293143a45727979d27dabd28e538a9668a
Size: 20.97 kB - fence-agents-intelmodular-4.10.0-62.el9_4.3.noarch.rpm
MD5: 9ba6586536187f7c2f060ea9b9c85977
SHA-256: 99d279a94d4d519ad306048a01c4a4b0e8189758b05fedadd6d6e60e41ca7f95
Size: 15.20 kB - fence-agents-ipdu-4.10.0-62.el9_4.3.noarch.rpm
MD5: 9a6cdbb1fb16ee0b1141d9d55b2e1765
SHA-256: 4db410a3bd1d7962497abe0dceef57cc017fe3503cce85eb0c5240a4c2a5cdc2
Size: 15.43 kB - fence-agents-ipmilan-4.10.0-62.el9_4.3.noarch.rpm
MD5: 140a7870c88acffe0bd19a48567cc4aa
SHA-256: fe5d3a36dc34bcca44980227138a896a4ad4f8125bcb1cdcfd9a75d813cffb8a
Size: 33.36 kB - fence-agents-kdump-4.10.0-62.el9_4.3.x86_64.rpm
MD5: b70e0629f4d6afccd37024c943f6705a
SHA-256: 8859a7607176a73ace4f15ea4da6049d093ff45f6915c3344a0ed8443d06aa90
Size: 27.69 kB - fence-agents-kubevirt-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 25cc4c0d2041ada7f3518adec321048a
SHA-256: 6678409befe0adc90f35fc403dcd1f619c8fd6eabd7fa21e75ae002dc6625f3d
Size: 4.55 MB - fence-agents-mpath-4.10.0-62.el9_4.3.noarch.rpm
MD5: 76ff270a218a2147230b18fe8ca640cb
SHA-256: 980e7c892eea2ff2f758187c5fc64cc77fe4311c54727023fe2225e76a9a7257
Size: 17.79 kB - fence-agents-openstack-4.10.0-62.el9_4.3.x86_64.rpm
MD5: fec555f65971a5416ae644322cc16542
SHA-256: 0445514ce21ff43680e5630ec0fbf11a0ba1cf1a91c90c7d3ea17c08c2306e59
Size: 16.84 kB - fence-agents-redfish-4.10.0-62.el9_4.3.x86_64.rpm
MD5: d31484e59b5dd38ab9d371c230c80fc6
SHA-256: 5256850f12e8e8faf9ec6bc6953239fe5bcf127d3f309c9e8797d3ffd2860025
Size: 15.75 kB - fence-agents-rhevm-4.10.0-62.el9_4.3.noarch.rpm
MD5: b4f6f26c74588beb0e1169be691d6bd3
SHA-256: 8b22ddce72d849bc4093f68691f2b3295179699fb819546d7d83eb5c2cf76f72
Size: 16.04 kB - fence-agents-rsa-4.10.0-62.el9_4.3.noarch.rpm
MD5: 88396277ffc7e41d42cd0e10ef4eb5a2
SHA-256: f4542f131d3edc02072f55aa84ea039a015b13261826345e6a9cd5efc2582c44
Size: 14.76 kB - fence-agents-rsb-4.10.0-62.el9_4.3.noarch.rpm
MD5: 261e1cf3fa11f2c1cc314d09d8612961
SHA-256: 4c760b76d5e11573e19c5495cb664baef8e524a303c6e53db90a2db08c58c412
Size: 14.81 kB - fence-agents-sbd-4.10.0-62.el9_4.3.noarch.rpm
MD5: c30cf56d222333cdaa3c9e588db52918
SHA-256: 93a27dc3cee779f49973d8d8aa192f723174f21c6d7681dc95adcf75a8734585
Size: 16.43 kB - fence-agents-scsi-4.10.0-62.el9_4.3.noarch.rpm
MD5: 34c719f723dd6e28029b753129f06fdc
SHA-256: 538864e839484c096ccc1979b6c2e144d1a47b5b39e956af2d0be2b6d2312c16
Size: 20.17 kB - fence-agents-virsh-4.10.0-62.el9_4.3.noarch.rpm
MD5: 5c4416f00d437f6b99a3c9c00cbd77b7
SHA-256: dcee8efbb2af59126b3cdb404c9ed8bf7909d3a3bb02fc57c845a6c12b3d10b7
Size: 15.34 kB - fence-agents-vmware-rest-4.10.0-62.el9_4.3.noarch.rpm
MD5: e634017002deb0c3b4c4ea6846133306
SHA-256: 03b65cced75a135b64ceea17b2ad239a39f59bc6a838fcc195e3bafe9c08d63c
Size: 16.00 kB - fence-agents-vmware-soap-4.10.0-62.el9_4.3.noarch.rpm
MD5: 59e00dec0f697d2873ee9867e6079e14
SHA-256: a4ad79971238c2b7507a57868ecfcbfbcc067ff314807e2e119cd23de9e775dc
Size: 16.94 kB - fence-agents-wti-4.10.0-62.el9_4.3.noarch.rpm
MD5: e5da7dd81420efcaca4ad217fb2a7191
SHA-256: 122780e18d8ccc627c69c9d960b1368b5867d1d7300f6411d06d298af10d9505
Size: 16.35 kB - fence-virt-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 48959129697f81e155bde4af95d86e47
SHA-256: bd206776da4140a6d31b1dc95763beb0a426976e433108623ccc5765a31ad516
Size: 39.59 kB - fence-virtd-4.10.0-62.el9_4.3.x86_64.rpm
MD5: f7683405ead8fe7244e5c8e46851e783
SHA-256: 08c993b3e184a5e6488357301efe9e9be5c80838bb9d0fbf680b6e989383b79e
Size: 52.99 kB - fence-virtd-cpg-4.10.0-62.el9_4.3.x86_64.rpm
MD5: df47ccef470a871b0db1b251ac1a020a
SHA-256: c53bd3eae66327d5c9326cfc6584c024ab686d409bea0feb0285b7ab128022e1
Size: 35.93 kB - fence-virtd-libvirt-4.10.0-62.el9_4.3.x86_64.rpm
MD5: c8a8c770a5e0b53658f014f8ccfc438b
SHA-256: 80ab15917b17b7e55c430571f0172d63db17fd51e5d5c21f665de710a7f18604
Size: 32.44 kB - fence-virtd-multicast-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 1cf659cac6374d395751ef149c80a6ef
SHA-256: 3d39e584ae39dccd730c6039d45cb2e5dccc3a8e95523f587e1702f647fe39c2
Size: 29.37 kB - fence-virtd-serial-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 02b489bb2843825fa3231f7775b6fa99
SHA-256: 99def01940114ef3d85aa3a1c47c8cc001a641ac4cf4a1f1740861507dc29603
Size: 32.90 kB - fence-virtd-tcp-4.10.0-62.el9_4.3.x86_64.rpm
MD5: e6fb29635900a8600183da009146110a
SHA-256: 92d1dff675c9ec31a0373e81823fdc26332dd42fdad82d38ede8783e6fd9102e
Size: 28.93 kB - ha-cloud-support-4.10.0-62.el9_4.3.x86_64.rpm
MD5: 2babb9df24cab1ef2efe709c9c92b550
SHA-256: 6ad6b7af9b8f25a74685a1760c445e6eda8b6285c005ee635b9d9195ab867b1e
Size: 40.66 MB