-
Bug
-
Resolution: Done-Errata
-
Undefined
-
6.13.z, 6.14.z, 6.15.z, 6.16.0
-
False
-
-
False
-
foreman-installer-3.12.0-1
-
0
-
Endeavour, Platform
-
-
-
Automated
-
Yes
Description of problem:
ssia
How reproducible:
always
Is this issue a regression from an earlier version:
Not a regression from an earlier version of Satellite. There were some cve fixes in apache-2.4.60, which (probably) got backported into httpd-2.4.37-65 which seems to have landed in both RHEL8 and 9. These cve fixes forbid the behavior we were relying on, unless we explicitly allow it with a flag.
Steps to Reproduce:
1. Enable cockpit integration
2. Try to access web console of a host
Actual behavior:
403 forbidden, "AH: Unsafe URL with %3f URL rewritten without UnsafeAllow3F" in foreman-ssl_error_ssl.log
Expected behavior:
Web console of remote host gets displayed.{}
- duplicates
-
SAT-27802 issue with web console when upgrading from 6.15.2 to 6.15.3
- Closed
- links to
-
RHBA-2024:140284 Important: Satellite 6.16.0 release