Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
If the postgresql service is running, it will be automatically restarted
after installing this update. After installing the updated packages, the
httpd daemon will be restarted automatically.
Red Hat CloudForms Management Engine delivers the insight, control, and
automation needed to address the challenges of managing virtual
environments. CloudForms Management Engine is built on Ruby on Rails, a
model-view-controller (MVC) framework for web application development.
Action Pack implements the controller and the view components.
Security Fix(es):
* A flaw was found in CloudForms in the self-service UI snapshot feature
where the name field is not properly sanitized for HTML and JavaScript
input. An attacker could use this flaw to execute a stored XSS attack on an
application administrator using CloudForms. Please note that CSP (Content
Security Policy) prevents exploitation of this XSS however not all browserssupport CSP. (CVE-2017-15125)
This issue was discovered by Yadnyawalk Tale (Red Hat).
Additional Changes:
This update also fixes several bugs and adds various enhancements.
Documentation for these changes is available from the Release Notes
document linked to in the References section.
https://access.redhat.com/security/cve/CVE-2017-15125 https://access.redhat.com/security/updates/classification/#moderate
CloudForms Management Engine 5.9:
Source:
ansible-2.4.3.0-1.el7ae.src.rpm
ansible-tower-3.1.5-3.el7at.src.rpm
bubblewrap-0.1.7-1.el7.src.rpm
cfme-5.9.0.22-1.el7cf.src.rpm
cfme-amazon-smartstate-5.9.0.22-1.el7cf.src.rpm
cfme-appliance-5.9.0.22-1.el7cf.src.rpm
cfme-gemset-5.9.0.22-1.el7cf.src.rpm
dbus-api-service-1.0.1-2.el7cf.src.rpm
dumb-init-1.2.0-1.el7.src.rpm
erlang-19.0.4-1.el7at.src.rpm
freeipmi-1.5.1-2.el7cf.src.rpm
google-compute-engine-2.0.0-1.el7cf.src.rpm
google-config-2.0.0-1.el7cf.src.rpm
httpd-configmap-generator-0.2.1-1.el7cf.src.rpm
nginx-1.10.2-1.el7at.src.rpm
postgresql94-9.4.15-3PGDG.el7at.src.rpm
prince-9.0r2-10.el7cf.src.rpm
python-crypto-2.6.1-16.el7at.src.rpm
python-jmespath-0.9.0-4.el7ae.src.rpm
python-meld3-0.6.10-1.el7.src.rpm
python-paramiko-2.1.1-2.el7ae.src.rpm
qpid-proton-0.19.0-1.el7cf.src.rpm
rabbitmq-server-3.6.9-1.el7at.src.rpm
rh-postgresql95-postgresql-pglogical-2.1.0-2.el7cf.src.rpm
rh-postgresql95-repmgr-3.1.3-2.el7cf.src.rpm
rh-ruby23-rubygem-bcrypt-3.1.11-1.el7cf.src.rpm
rh-ruby23-rubygem-ffi-1.9.18-1.el7cf.src.rpm
rh-ruby23-rubygem-hamlit-2.7.5-1.el7cf.src.rpm
rh-ruby23-rubygem-http_parser.rb-0.6.0-1.el7cf.src.rpm
rh-ruby23-rubygem-json-2.0.4-1.el7cf.src.rpm
rh-ruby23-rubygem-linux_block_device-0.2.1-1.el7cf.src.rpm
Read the Full Advisory
An update is now available for CloudForms Management Engine 5.9.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
CloudForms Management Engine 5.9 - noarch, x86_64
1253012 - [RFE] Custom button filtering mechanism needed
1334930 - [RFE] Customer asking how to delete host instance using automate
1335989 - Automate: customize_request method in Redhat domain incorrect sets security_group value in options hash
1339612 - Vmdb Last Start Time bad date
1341502 - Can't collect logs to subfolder using anonymous ftp connection
1341867 - [RFE] SmartState Analysis for OpenStack instances booted from Cinder volume
1371222 - EC2 autorefresh works only for items associated to instance/image
1373076 - [RFE] Publish VM to a template
1375506 - [RFE] Charge volume types differently.
1379185 - [RFE] Allow to configure OpenSCAP CVE definitions URL
1389660 - [RFE] Extend custom buttons visibility criteria
1393038 - [RFE] Display System Default Timeout Value in Reports
1393655 - HTML character codes while accessing the vm/templates page under a folder which has '/' in name
1393681 - Unsupported content type 'menu' ERROR in logs when generating Menu Widget for user
1395011 - 'Monthly Host Count per Provider' report should not contain public cloud providers1395013 - 'Monthly Host Count per Provider' report should not contain Container providers1395356 - [RFE] Targeted Refresh for Amazon VMs in via vm_object.refresh method
1395757 - [RFE] Cloud-Init Scripts in Google's Compute Engine
1395782 - Trying to connect to VM console randomly fails on RHV environments
Get the latest Linux and open source security news straight to your inbox.