Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
Red Hat CloudForms Management Engine delivers the insight, control, and
automation needed to address the challenges of managing virtual
environments. CloudForms Management Engine is built on Ruby on Rails, a
model-view-controller (MVC) framework for web application development.
Action Pack implements the controller and the view components.
The following packages have been upgraded to a later upstream version:
ansible-tower (3.1.5), cfme (5.8.2.3), cfme-appliance (5.8.2.3),
cfme-gemset (5.8.2.3), rabbitmq-server (3.6.9), rh-ruby23-rubygem-nokogiri
(1.8.1), supervisor (3.1.4). (BZ#1476286, BZ#1485484)
Security Fix(es):
* A flaw was found in Tower's interface with SCM repositories. If a Tower
project (SCM repository) definition does not have the 'delete before
update' flag set, an attacker with commit access to the upstream playbook
source repository could create a Trojan playbook that, when executed by
Tower, modifies the checked out SCM repository to add git hooks. These git
hooks could, in turn, cause arbitrary command and code execution as the
user Tower runs as. (CVE-2017-12148)
* A vulnerability was found in the XML-RPC interface in supervisord. When
processing malformed commands, an attacker can cause arbitrary shell
commands to be executed on the server as the same user as supervisord.
Exploitation requires the attacker to first be authenticated to the
supervisord service. (CVE-2017-11610)
The CVE-2017-12148 issue was discovered by Ryan Petrello (Red Hat).
Additional Changes:
This update also fixes several bugs and adds various enhancements.
Documentation for these changes is available from the Release Notes
document linked to in the References section.
https://access.redhat.com/security/cve/CVE-2017-11610 https://access.redhat.com/security/cve/CVE-2017-12148 https://access.redhat.com/security/updates/classification#important
CloudForms Management Engine 5.8:
Source:
cfme-5.8.2.3-1.el7cf.src.rpm
cfme-appliance-5.8.2.3-1.el7cf.src.rpm
cfme-gemset-5.8.2.3-1.el7cf.src.rpm
rabbitmq-server-3.6.9-1.el7at.src.rpm
rh-ruby23-rubygem-nokogiri-1.8.1-2.el7cf.src.rpm
supervisor-3.1.4-1.el7.src.rpm
noarch:
rabbitmq-server-3.6.9-1.el7at.noarch.rpm
supervisor-3.1.4-1.el7.noarch.rpm
x86_64:
ansible-tower-server-3.1.5-1.el7at.x86_64.rpm
ansible-tower-setup-3.1.5-1.el7at.x86_64.rpm
cfme-5.8.2.3-1.el7cf.x86_64.rpm
cfme-appliance-5.8.2.3-1.el7cf.x86_64.rpm
cfme-appliance-debuginfo-5.8.2.3-1.el7cf.x86_64.rpm
cfme-debuginfo-5.8.2.3-1.el7cf.x86_64.rpm
cfme-gemset-5.8.2.3-1.el7cf.x86_64.rpm
rh-ruby23-rubygem-nokogiri-1.8.1-2.el7cf.x86_64.rpm
rh-ruby23-rubygem-nokogiri-debuginfo-1.8.1-2.el7cf.x86_64.rpm
rh-ruby23-rubygem-nokogiri-doc-1.8.1-2.el7cf.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key
An update is now available for CloudForms Management Engine 5.8.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
CloudForms Management Engine 5.8 - noarch, x86_64
1439650 - Tenant and catalog information missing in Service Catalog Item Being Tagged
1459987 - Changes to timeout setting should not require evmserverd restart
1459996 - [RFE] Add support for virt v2v
1460754 - containers: containers analysis task results - user is system and owner is empty
1461061 - Add rate view option for counters in Ad-hoc Metrics
1465087 - Service template provisioning request do not honour quotas
1465089 - "Items" keyword in the dropdown list values of Default Items Per Page in my settings
1471709 - Default landing page is not showing "storage page" related options for custom made role
1476143 - CVE-2017-11610 supervisor: Command injection via malicious XML-RPC request
1477194 - AD with external auth, When doing group lookup for user group SID number is displayed instead of Group name
1477616 - Validation failed: Status is not included in the list
1477701 - Error caught: [NoMethodError] undefined method `[]' for nil:NilClass for REGULAR EXPRESSION MATCHES report
1477702 - UI: Unable to edit Compliance Policy Scope condition.
1478367 - 400 Bad Request Provision Error
1478372 - All start page entries must be updated to include the new navigation
1478379 - We do not check the base unit when creating the unit label
1478391 - Limit ansible playbook catalog item description
1478398 - Fields change in Advanced search in Automation -> Ansible Tower page
Get the latest Linux and open source security news straight to your inbox.