Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Red Hat 5.9 Moderate: XSS in CloudForms Management Update RHSA-2018-0380-01

red hat
Calendar Grey March 1, 2018
Scroller Redhat
Timely security patch for Red Hat CloudForms combats cross-site scripting vulnerabilities and features multiple bug resolutions. Implement without delay.
An update is now available for CloudForms Management Engine 5.9

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

If the postgresql service is running, it will be automatically restarted after installing this update. After installing the updated packages, the httpd daemon will be restarted automatically.

Summary

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.
Security Fix(es):
* A flaw was found in CloudForms in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. Please note that CSP (Content Security Policy) prevents exploitation of this XSS however not all browserssupport CSP. (CVE-2017-15125)
This issue was discovered by Yadnyawalk Tale (Red Hat).
Additional Changes:
This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

References

https://access.redhat.com/security/cve/CVE-2017-15125 https://access.redhat.com/security/updates/classification/#moderate

Package List

CloudForms Management Engine 5.9:
Source: ansible-2.4.3.0-1.el7ae.src.rpm ansible-tower-3.1.5-3.el7at.src.rpm bubblewrap-0.1.7-1.el7.src.rpm cfme-5.9.0.22-1.el7cf.src.rpm cfme-amazon-smartstate-5.9.0.22-1.el7cf.src.rpm cfme-appliance-5.9.0.22-1.el7cf.src.rpm cfme-gemset-5.9.0.22-1.el7cf.src.rpm dbus-api-service-1.0.1-2.el7cf.src.rpm dumb-init-1.2.0-1.el7.src.rpm erlang-19.0.4-1.el7at.src.rpm freeipmi-1.5.1-2.el7cf.src.rpm google-compute-engine-2.0.0-1.el7cf.src.rpm google-config-2.0.0-1.el7cf.src.rpm httpd-configmap-generator-0.2.1-1.el7cf.src.rpm nginx-1.10.2-1.el7at.src.rpm postgresql94-9.4.15-3PGDG.el7at.src.rpm prince-9.0r2-10.el7cf.src.rpm python-crypto-2.6.1-16.el7at.src.rpm python-jmespath-0.9.0-4.el7ae.src.rpm python-meld3-0.6.10-1.el7.src.rpm python-paramiko-2.1.1-2.el7ae.src.rpm qpid-proton-0.19.0-1.el7cf.src.rpm rabbitmq-server-3.6.9-1.el7at.src.rpm rh-postgresql95-postgresql-pglogical-2.1.0-2.el7cf.src.rpm rh-postgresql95-repmgr-3.1.3-2.el7cf.src.rpm rh-ruby23-rubygem-bcrypt-3.1.11-1.el7cf.src.rpm rh-ruby23-rubygem-ffi-1.9.18-1.el7cf.src.rpm rh-ruby23-rubygem-hamlit-2.7.5-1.el7cf.src.rpm rh-ruby23-rubygem-http_parser.rb-0.6.0-1.el7cf.src.rpm rh-ruby23-rubygem-json-2.0.4-1.el7cf.src.rpm rh-ruby23-rubygem-linux_block_device-0.2.1-1.el7cf.src.rpm

Read the Full Advisory


Advisory ID: RHSA-2018:0380-01
Product: Red Hat CloudForms
Issue date: 2018-03-01

Topic

An update is now available for CloudForms Management Engine 5.9.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

CloudForms Management Engine 5.9 - noarch, x86_64

Bugs Fixed

1253012 - [RFE] Custom button filtering mechanism needed

1334930 - [RFE] Customer asking how to delete host instance using automate

1335989 - Automate: customize_request method in Redhat domain incorrect sets security_group value in options hash

1339612 - Vmdb Last Start Time bad date

1341502 - Can't collect logs to subfolder using anonymous ftp connection

1341867 - [RFE] SmartState Analysis for OpenStack instances booted from Cinder volume

1371222 - EC2 autorefresh works only for items associated to instance/image

1373076 - [RFE] Publish VM to a template

1375506 - [RFE] Charge volume types differently.

1379185 - [RFE] Allow to configure OpenSCAP CVE definitions URL

1389660 - [RFE] Extend custom buttons visibility criteria

1393038 - [RFE] Display System Default Timeout Value in Reports

1393655 - HTML character codes while accessing the vm/templates page under a folder which has '/' in name

1393681 - Unsupported content type 'menu' ERROR in logs when generating Menu Widget for user

1395011 - 'Monthly Host Count per Provider' report should not contain public cloud providers1395013 - 'Monthly Host Count per Provider' report should not contain Container providers1395356 - [RFE] Targeted Refresh for Amazon VMs in via vm_object.refresh method

1395757 - [RFE] Cloud-Init Scripts in Google's Compute Engine

1395782 - Trying to connect to VM console randomly fails on RHV environments

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.