OLAMSA-2025-0007

OLAMSA-2025-0007 - ol-automation-manager security update

Type:SECURITY
Impact:CRITICAL
Release Date:2025-06-09

Description


ol-automation-manager
[2.2.0-38.el8]
- Fix for CVE-2024-53907
- Fix for CVE-2024-53908

[2.2.0-37.el8]
- OLAM-823 Apply patch for CVE-2024-56326 ( Jinja2 3.1.2 )

[2.2.0-36.el8]
- OLAM-796 Fix for CVE-2024-53907 (Django 4.2.6)

[2.2.0-35.el8]
- OLAM-787 Apply patch for CVE-2024-4067 ( micromatch 4.0.2, 4.0.7 )

python-jinja2
[3.1.3-1.0.5]
- Apply patch for CVE-2024-56326 [JIRA: OLAM-823]

[3.1.3-1.0.4]
- Apply patch for CVE-2025-27516 [JIRA: OLAM-708]

[3.1.3-1.0.3]
- Apply patch for CVE-2024-56201 [JIRA: OLAM-683]

[3.1.3-1.0.2]
- Update to 3.1.3
- Rebuild with python 3.11

[3.1.2-1.0.2]
- Add 3rd party licenses

[3.1.2-1.0.1]
- Rebuild for Python 3.9 [JIRA: OLAM-32]

* Tue Sep 20 2022 Odilon Sousa 3.1.2-1
- Update to 3.1.2

[3.0.3-2]
- Build against python 3.9

[3.0.3-1]
- Release python-jinja2 3.0.3

[3.0.2-1]
- Release python-jinja2 3.0.2

* Mon Sep 06 2021 Evgeni Golov - 2.11.3-2
- Build against Python 3.8

* Fri Mar 19 2021 Evgeni Golov 2.11.3-1
- Update to 2.11.3

* Tue Apr 14 2020 Evgeni Golov 2.11.2-1
- Update to 2.11.2

[2.11.1-2]
- Bump release to build for el8

* Wed Feb 05 2020 Evgeni Golov 2.11.1-1
- Update to 2.11.1

* Mon Nov 18 2019 Evgeni Golov - 2.10.3-1
- Initial package.

python-pulpcore
[3.28.26-1.0.6]
- OLAM-510 Fix for CVE-2024-7143

[3.28.26-1.0.5]
- Add psycopg requires

[3.28.26-1.0.4]
- Replace psycopg[binary] with psycopg-c requirement

[3.28.26-1.0.3]
- Removes async-timeout as a dependency

[3.28.26-1.0.2]
- Use autogenerated pulpcore dependencies instead of manual ones.

[3.28.26-1.0.1]
- Update to 3.28.26
- Rebuild with python 3.11
- drop cryptography.patch

[3.21.4-1.0.2]
- Add NOTICE and THIRD_PARTY_LICENSES.txt

[3.21.4-1.0.1]
- Rebuild for Python 3.9 [JIRA: OLAM-32]

[3.21.4-1]
- Release python-pulpcore 3.21.4

* Tue Sep 20 2022 Odilon Sousa 3.21.0-1
- Update to 3.21.0

[3.18.10-1]
- Release python-pulpcore 3.18.10

[3.18.6-1]
- Release python-pulpcore 3.18.6

[3.18.5-2]
- Adding a sed to change redis on requirements.txt, from ~= to >=

[3.18.5-1]
- Release python-pulpcore 3.18.5

[3.18.4-4]
- Obsolete the old Python 3.8 package for smooth upgrade

[3.18.4-3]
- Fixing pulpcore requirements for djangorestframework

[3.18.4-2]
- Fixing the requirement for url-normalize

[3.18.4-1]
- Release python-pulpcore 3.18.4

[3.17.3-2]
- Build against python 3.9

[3.17.3-1]
- Release python-pulpcore 3.17.3

[3.16.1-1]
- update to 3.16.1

[3.16.0-2]
- Solving conflict with django-filter

[3.16.0-1]
- Release python-pulpcore 3.16.0

* Tue Oct 26 2021 Evgeni Golov - 3.15.2-4
- Also obsolete python3-pulpcore on EL7

* Wed Oct 20 2021 Evgeni Golov - 3.15.2-3
- Add provides for 'pulpcore'

* Wed Sep 29 2021 Evgeni Golov - 3.15.2-2
- Obsolete the old Python 3.6 package for smooth upgrade

* Wed Sep 08 2021 Evgeni Golov 3.15.2-1
- Update to 3.15.2

[3.14.5-2]
- Release python-pulpcore 3.14.5

[3.14.5-1]
- Release python-pulpcore 3.14.5

[3.14.4-1]
- Release python-pulpcore 3.14.4

[3.14.3-1]
- upgrade to 3.14.3

[3.14.1-1]
- update to 3.14.1

* Fri Jul 02 2021 Evgeni Golov - 3.14.0-1
- Release python-pulpcore 3.14.0

* Thu Jun 17 2021 Evgeni Golov - 3.13.0-2
- place the worker wrapper in libexec

* Fri Jun 11 2021 Evgeni Golov 3.13.0-1
- Update to 3.13.0

* Mon May 31 2021 Evgeni Golov - 3.11.2-1
- Release python-pulpcore 3.11.2

* Wed May 12 2021 Evgeni Golov 3.11.1-1
- Update to 3.11.1

[3.11.0-2]
- add patch for issue 8603

* Fri Mar 19 2021 Evgeni Golov 3.11.0-1
- Update to 3.11.0

* Wed Mar 03 2021 Brian Bouterse - 3.9.1-2
- Increase Pulp worker timeout to 300 seconds

* Fri Jan 22 2021 Evgeni Golov - 3.9.1-1
- Release python-pulpcore 3.9.1

* Mon Jan 11 2021 Evgeni Golov - 3.9.0-1
- Update to 3.9.0

* Mon Dec 21 2020 Evgeni Golov - 3.8.1-2
- Drop django-storages requirement, it was an oversight to add it

* Fri Dec 11 2020 Evgeni Golov 3.8.1-1
- Update to 3.8.1

* Tue Nov 03 2020 Evgeni Golov 3.7.3-1
- Update to 3.7.3

* Fri Oct 23 2020 Evgeni Golov - 3.7.2-1
- Release python-pulpcore 3.7.2

* Fri Oct 09 2020 Evgeni Golov - 3.7.1-3
- Bump dynaconf Requires to skip RCs

[3.7.1-2]
- Add libexec wrappers for gunicorn and rq

* Wed Sep 30 2020 Evgeni Golov 3.7.1-1
- Update to 3.7.1

* Mon Sep 07 2020 Evgeni Golov 3.6.3-1
- Update to 3.6.3

[3.6.2-2]
- add missing jinja2 dep

* Thu Sep 03 2020 Evgeni Golov 3.6.2-1
- Update to 3.6.2

* Tue Aug 25 2020 Evgeni Golov 3.6.0-1
- Update to 3.6.0

* Thu Jun 04 2020 Evgeni Golov 3.4.1-1
- Update to 3.4.1

* Fri May 08 2020 Evgeni Golov 3.3.1-1
- Update to 3.3.1

* Tue Apr 28 2020 Evgeni Golov 3.3.0-1
- Update to 3.3.0

* Wed Mar 18 2020 Samir Jha 3.2.1-1
- Update to 3.2.1

[3.0.1-2]
- Bump release to build for el8

* Fri Jan 17 2020 Evgeni Golov 3.0.1-1
- Update to 3.0.1

* Fri Dec 13 2019 Evgeni Golov 3.0.0-1
- Update to 3.0.0

* Mon Nov 18 2019 Evgeni Golov - 3.0.0rc8-1
- Initial package.


Related CVEs


CVE-2024-53908
CVE-2024-7143
CVE-2024-56326
CVE-2024-4067
CVE-2024-53907

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (x86_64) ol-automation-manager-2.2.0-38.el8.src.rpm2ee133e749a47b33541fb3f214bd3be273240e5244fd903525e4bc96028039b2-ol8_x86_64_automation2.2
python-jinja2-3.1.3-1.0.5.el8.src.rpmac48d3cb3e261200f46700f534044794a63ea014a325299cd094f63174bbf7fc-ol8_x86_64_automation2.2
python-pulpcore-3.28.26-1.0.6.el8.src.rpmba58f7defda99d85f4b9a63ef87b109c16fee8166cc593988f9d5b861398a2f0-ol8_x86_64_automation2.2
ol-automation-manager-2.2.0-38.el8.x86_64.rpm2120819a0070f75d1ec3504011b1298a66773b7ca01eda2ee0a31f40e4d4f758-ol8_x86_64_automation2.2
ol-automation-manager-cli-2.2.0-38.el8.noarch.rpm5e61899152460227bec77a2df2f3d88b204ddee39453187c74d79bbba0595774-ol8_x86_64_automation2.2
python3.11-jinja2-3.1.3-1.0.5.el8.noarch.rpm07892f707f729f081541f4b8128ba07ec0212faeff8c11314e4d2e9eb8237d48-ol8_x86_64_automation2.2
python3.11-pulpcore-3.28.26-1.0.6.el8.noarch.rpm7e1d1d1be07cfca202190a532b9af88113e45ace3a5cc80ed50b13baa62c4536-ol8_x86_64_automation2.2
python311-olamkit-2.2.0-38.el8.noarch.rpm8e8762a1847564b18cb28d7a5381cf4d56f39defa45342005cbb6842f21b2a78-ol8_x86_64_automation2.2



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete