Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Red Hat CloudForms 5.8 RHSA-2017-3005 Important Security Advisory

red hat
Calendar Grey October 24, 2017
Scroller Redhat
Crucial announcement regarding the resolution of vulnerabilities and glitches within Red Hat CloudForms Management Engine version 5.8.
An update is now available for CloudForms Management Engine 5.8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.
The following packages have been upgraded to a later upstream version: ansible-tower (3.1.5), cfme (5.8.2.3), cfme-appliance (5.8.2.3), cfme-gemset (5.8.2.3), rabbitmq-server (3.6.9), rh-ruby23-rubygem-nokogiri (1.8.1), supervisor (3.1.4). (BZ#1476286, BZ#1485484)
Security Fix(es):
* A flaw was found in Tower's interface with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository could create a Trojan playbook that, when executed by Tower, modifies the checked out SCM repository to add git hooks. These git hooks could, in turn, cause arbitrary command and code execution as the user Tower runs as. (CVE-2017-12148)
* A vulnerability was found in the XML-RPC interface in supervisord. When processing malformed commands, an attacker can cause arbitrary shell commands to be executed on the server as the same user as supervisord. Exploitation requires the attacker to first be authenticated to the supervisord service. (CVE-2017-11610)
The CVE-2017-12148 issue was discovered by Ryan Petrello (Red Hat).
Additional Changes:
This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

References

https://access.redhat.com/security/cve/CVE-2017-11610 https://access.redhat.com/security/cve/CVE-2017-12148 https://access.redhat.com/security/updates/classification#important

Package List

CloudForms Management Engine 5.8:
Source: cfme-5.8.2.3-1.el7cf.src.rpm cfme-appliance-5.8.2.3-1.el7cf.src.rpm cfme-gemset-5.8.2.3-1.el7cf.src.rpm rabbitmq-server-3.6.9-1.el7at.src.rpm rh-ruby23-rubygem-nokogiri-1.8.1-2.el7cf.src.rpm supervisor-3.1.4-1.el7.src.rpm
noarch: rabbitmq-server-3.6.9-1.el7at.noarch.rpm supervisor-3.1.4-1.el7.noarch.rpm
x86_64: ansible-tower-server-3.1.5-1.el7at.x86_64.rpm ansible-tower-setup-3.1.5-1.el7at.x86_64.rpm cfme-5.8.2.3-1.el7cf.x86_64.rpm cfme-appliance-5.8.2.3-1.el7cf.x86_64.rpm cfme-appliance-debuginfo-5.8.2.3-1.el7cf.x86_64.rpm cfme-debuginfo-5.8.2.3-1.el7cf.x86_64.rpm cfme-gemset-5.8.2.3-1.el7cf.x86_64.rpm rh-ruby23-rubygem-nokogiri-1.8.1-2.el7cf.x86_64.rpm rh-ruby23-rubygem-nokogiri-debuginfo-1.8.1-2.el7cf.x86_64.rpm rh-ruby23-rubygem-nokogiri-doc-1.8.1-2.el7cf.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:3005-01
Product: Red Hat CloudForms
Issue date: 2017-10-24
Cross references: RHSA-2017:1758

Topic

An update is now available for CloudForms Management Engine 5.8.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

CloudForms Management Engine 5.8 - noarch, x86_64

Bugs Fixed

1439650 - Tenant and catalog information missing in Service Catalog Item Being Tagged

1459987 - Changes to timeout setting should not require evmserverd restart

1459996 - [RFE] Add support for virt v2v

1460754 - containers: containers analysis task results - user is system and owner is empty

1461061 - Add rate view option for counters in Ad-hoc Metrics

1465087 - Service template provisioning request do not honour quotas

1465089 - "Items" keyword in the dropdown list values of Default Items Per Page in my settings

1471709 - Default landing page is not showing "storage page" related options for custom made role

1476143 - CVE-2017-11610 supervisor: Command injection via malicious XML-RPC request

1477194 - AD with external auth, When doing group lookup for user group SID number is displayed instead of Group name

1477616 - Validation failed: Status is not included in the list

1477701 - Error caught: [NoMethodError] undefined method `[]' for nil:NilClass for REGULAR EXPRESSION MATCHES report

1477702 - UI: Unable to edit Compliance Policy Scope condition.

1478367 - 400 Bad Request Provision Error

1478372 - All start page entries must be updated to include the new navigation

1478379 - We do not check the base unit when creating the unit label

1478391 - Limit ansible playbook catalog item description

1478398 - Fields change in Advanced search in Automation -> Ansible Tower page

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.