-
Bug
-
Resolution: Done
-
Major
-
None
-
None
-
Moderate
-
False
-
False
-
** Note that this is a public ticket, please refrain from adding any sensitive data. **
Description:
False positive for CVE 2022-32224 even after all packages have been updated listed in the RHSA-2023:1151 - Security Advisory. Installed packages: foreman-3.1.1.26-1.el7sat.noarch Wed Jun 7 12:01:59 2023 tfm-rubygem-activerecord-6.0.6-2.el7sat.noarch Wed Jun 7 12:01:25 2023 satellite-6.11.5.3-1.el7sat.noarch Wed Jun 7 12:02:48 2023 [1]https://access.redhat.com/security/cve/CVE-2022-32224 [2]https://access.redhat.com/errata/RHSA-2023:1151
Steps to Reproduce:
1. Register Satellite 6.11 with Insights 2. Run 'insights-client' command
How reproducible: (Always / Intermittent / Random)
Always
Actual Results:
Even after installing RHSA-2023:1151 errata, satellite server is flagged with CVE 2022-32224
Expected results:
CVE 2022-32224 should be removed from the satellite host profile in Insights UI.