Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Red Hat CloudForms 5.9 RHSA-2018-2184-01 Moderate: Secrets Exposure in Logs

red hat
Calendar Grey July 12, 2018
Scroller Redhat
The latest release of CloudForms 4.6.3 resolves a security vulnerability of moderate severity, delivering essential updates and improvements.
An update is now available for CloudForms Management Engine 5.9

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.
Security fix(es):
* ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs (CVE-2018-10855)
Red Hat would like to thank Tobias Henkel (BMW Car IT GmbH) for reporting these issues.
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document.

References

https://access.redhat.com/security/cve/CVE-2018-10855 https://access.redhat.com/security/updates/classification#moderate

Package List

CloudForms Management Engine 5.9:
Source: ansible-2.4.5.0-1.el7ae.src.rpm ansible-tower-3.2.5-1.el7at.src.rpm cfme-5.9.3.4-1.el7cf.src.rpm cfme-amazon-smartstate-5.9.3.4-1.el7cf.src.rpm cfme-appliance-5.9.3.4-1.el7cf.src.rpm cfme-gemset-5.9.3.4-1.el7cf.src.rpm httpd-configmap-generator-0.2.2-1.1.el7cf.src.rpm
noarch: ansible-2.4.5.0-1.el7ae.noarch.rpm ansible-doc-2.4.5.0-1.el7ae.noarch.rpm
x86_64: ansible-tower-3.2.5-1.el7at.x86_64.rpm ansible-tower-server-3.2.5-1.el7at.x86_64.rpm ansible-tower-setup-3.2.5-1.el7at.x86_64.rpm ansible-tower-ui-3.2.5-1.el7at.x86_64.rpm ansible-tower-venv-ansible-3.2.5-1.el7at.x86_64.rpm ansible-tower-venv-tower-3.2.5-1.el7at.x86_64.rpm cfme-5.9.3.4-1.el7cf.x86_64.rpm cfme-amazon-smartstate-5.9.3.4-1.el7cf.x86_64.rpm cfme-appliance-5.9.3.4-1.el7cf.x86_64.rpm cfme-appliance-common-5.9.3.4-1.el7cf.x86_64.rpm cfme-appliance-debuginfo-5.9.3.4-1.el7cf.x86_64.rpm cfme-appliance-tools-5.9.3.4-1.el7cf.x86_64.rpm cfme-debuginfo-5.9.3.4-1.el7cf.x86_64.rpm cfme-gemset-5.9.3.4-1.el7cf.x86_64.rpm cfme-gemset-debuginfo-5.9.3.4-1.el7cf.x86_64.rpm httpd-configmap-generator-0.2.2-1.1.el7cf.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key


Advisory ID: RHSA-2018:2184-01
Product: Red Hat CloudForms
Issue date: 2018-07-12
Cross references: RHSA-2018:1328

Topic

An update is now available for CloudForms Management Engine 5.9.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

CloudForms Management Engine 5.9 - noarch, x86_64

Bugs Fixed

1536677 - Simultaneous service catalog request do not honour quotas

1553227 - When editing ansible service catalog item the dialog radio button never appears1553383 - [RFE] Switch default refresh to graph refresh for RHV provider

1553795 - [RFE] Move database maintenance to the application

1563745 - appliance console showing removed option db maintenance

1565845 - Service buttons do not attach $evm.root['service']

1565925 - The value that is selected in the drop down is not passed to the $evm.root

1566570 - If the external network provider is unavailable CFME network provider throws unfriendly exception

1569170 - Help Documentation is only visible to users with super admin role

1571303 - [Regression] Unexpected error while opening GCE details page

1572760 - OSPD 13 Undercloud - Infrastructure Provider Network Manager does not refreshed

1574154 - Refresh Failing for VMware VIM object is too large

1574569 - OSPD 12 Undercloud - Infrastructure Provider refresh failed

1575713 - Unable to access the Help Documentation page due to "Authorization Error"

1576099 - total costs no longer showing in any chargeback report if they are the only columns in the report

1577247 - ansible-tower-setup installs several new non-Red Hat yum repositories

1578121 - [RHV] SSA is not retrieving file information from VM on RHV

1578124 - Incorrect storage type size in openstack cloud reports

1578125 - Cloud Volume creation error does not raise VM provision error

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.