Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

RedHat CloudForms 5.9 RHSA-2018:1328-01 Critical RCE Vulnerability Alert

red hat
Calendar Grey May 7, 2018
Scroller Redhat
Critical announcement for Red Hat CloudForms 4.6.2, focusing on vital security improvements and feature advancements.
An update is now available for CloudForms Management Engine 5.9

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.
Security Fix(es):
* python-paramiko: Authentication bypass in transport.py (CVE-2018-7750)
* ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges (CVE-2018-1101)
Red Hat would like to thank Graham Mainwaring of Red Hat for reporting CVE-2018-1101.
* ansible-tower: Remote code execution by users with access to define variables in job templates (CVE-2018-1104)
Red Hat would like to thank Simon Vikström for reporting CVE-2018-1104.
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

References

https://access.redhat.com/security/cve/CVE-2018-1101 https://access.redhat.com/security/cve/CVE-2018-1104 https://access.redhat.com/security/cve/CVE-2018-7750 https://access.redhat.com/security/updates/classification#important

Package List

CloudForms Management Engine 5.9:
Source: ansible-2.4.4.0-1.el7ae.src.rpm ansible-tower-3.2.4-1.el7at.src.rpm cfme-5.9.2.4-1.el7cf.src.rpm cfme-amazon-smartstate-5.9.2.4-1.el7cf.src.rpm cfme-appliance-5.9.2.4-1.el7cf.src.rpm cfme-gemset-5.9.2.4-1.el7cf.src.rpm dbus-api-service-1.0.1-3.el7cf.src.rpm httpd-configmap-generator-0.2.1-2.el7cf.src.rpm postgresql96-9.6.6-1PGDG.el7.src.rpm python-paramiko-2.1.1-4.el7.src.rpm rh-ruby23-rubygem-json-2.1.0-1.el7cf.src.rpm rh-ruby23-rubygem-qpid_proton-0.22.0-2.el7cf.src.rpm
noarch: ansible-2.4.4.0-1.el7ae.noarch.rpm ansible-doc-2.4.4.0-1.el7ae.noarch.rpm python-paramiko-2.1.1-4.el7.noarch.rpm python-paramiko-doc-2.1.1-4.el7.noarch.rpm rh-ruby23-rubygem-qpid_proton-doc-0.22.0-2.el7cf.noarch.rpm
x86_64: ansible-tower-3.2.4-1.el7at.x86_64.rpm ansible-tower-server-3.2.4-1.el7at.x86_64.rpm ansible-tower-setup-3.2.4-1.el7at.x86_64.rpm ansible-tower-ui-3.2.4-1.el7at.x86_64.rpm ansible-tower-venv-ansible-3.2.4-1.el7at.x86_64.rpm ansible-tower-venv-tower-3.2.4-1.el7at.x86_64.rpm cfme-5.9.2.4-1.el7cf.x86_64.rpm cfme-amazon-smartstate-5.9.2.4-1.el7cf.x86_64.rpm cfme-appliance-5.9.2.4-1.el7cf.x86_64.rpm cfme-appliance-common-5.9.2.4-1.el7cf.x86_64.rpm cfme-appliance-debuginfo-5.9.2.4-1.el7cf.x86_64.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2018:1328-01
Product: Red Hat CloudForms
Issue date: 2018-05-07
Cross references: RHBA-2018:0556

Topic

An update is now available for CloudForms Management Engine 5.9.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

CloudForms Management Engine 5.9 - noarch, x86_64

Bugs Fixed

1495849 - [ALL_LANG] VM or Template comparison screen has untranslated entries.

1510499 - With RHV Graph refresh template numbers in Provider inventory does not get updated correctly.

1526086 - [ALL_LANG] Compute - Containers - Container Builds page has missing translations

1526088 - [ALL_LANG] Compute - Containers - Pods page has missing translations

1530680 - xClarity: EvmRole-operator unable to view physical server summary page

1530760 - [ALL_LANG] Control - Explorer - Policy Profiles - All Policy Profiles : 'Policy' is not localized

1533220 - [ALL_LANG] Control - Explorer - Actions - All Actions - Configure - Add a new Action : 'Action Type' drop-down menu has untranslated entries

1533233 - On Tag Assignment page Category has other Tags than preconfigured for it

1533515 - [ALL_LANG] User Icon - Configuration - Access Control - Roles : Add new Role has untranslated entries

1538094 - [ALL_LANG] User Icon - Tasks : untranslated entry

1538100 - [ALL_LANG] User Icon - Configuration - Settings - CFME Region: Region xx[xx] has untranslated entry

1549625 - webui updates failing when a proxy is required

1549722 - WebUI: Tool tip displays html code while setting the ownership for multiple vm's

1550728 - Replication configuration page does not open when child database is down

1550730 - [Ansible Embedded] - Embedded Ansible cannot be enabled on IPv6 only appliance

1550736 - unable to view quotas without manage quota permissoin being enabled in 5.8.2

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.