RedHat: RHSA-2019-1429:01 Important: CloudForms 4.7.5 security,
Summary
Red Hat CloudForms Management Engine delivers the insight, control, and
automation needed to address the challenges of managing virtual
environments. CloudForms Management Engine is built on Ruby on Rails, a
model-view-controller (MVC) framework for web application development.
Action Pack implements the controller and the view components.
Security Fix(es):
* rubygems: Installing a malicious gem may lead to arbitrary code execution
(CVE-2019-8324)
* rubygems: Delete directory using symlink when decompressing tar
(CVE-2019-8320)
* rubygems: Escape sequence injection vulnerability in verbose
(CVE-2019-8321)
* rubygems: Escape sequence injection vulnerability in gem owner
(CVE-2019-8322)
* rubygems: Escape sequence injection vulnerability in API response
handling (CVE-2019-8323)
* rubygems: Escape sequence injection vulnerability in errors(CVE-2019-8325)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
This update fixes various bugs and adds enhancements. Documentation for
these changes is available from the Release Notes document linked to in the
References section.
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
If the postgresql service is running, it will be automatically restarted
after installing this update. After installing the updated packages, the
httpd daemon will be restarted automatically.
References
https://access.redhat.com/security/cve/CVE-2019-8320 https://access.redhat.com/security/cve/CVE-2019-8321 https://access.redhat.com/security/cve/CVE-2019-8322 https://access.redhat.com/security/cve/CVE-2019-8323 https://access.redhat.com/security/cve/CVE-2019-8324 https://access.redhat.com/security/cve/CVE-2019-8325 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.7/html/release_notes
Package List
CloudForms Management Engine 5.10:
Source:
cfme-5.10.5.1-1.el7cf.src.rpm
cfme-amazon-smartstate-5.10.5.1-1.el7cf.src.rpm
cfme-appliance-5.10.5.1-1.el7cf.src.rpm
cfme-gemset-5.10.5.1-1.el7cf.src.rpm
ruby-2.4.6-91.el7cf.src.rpm
noarch:
ruby-doc-2.4.6-91.el7cf.noarch.rpm
ruby-irb-2.4.6-91.el7cf.noarch.rpm
rubygem-minitest-5.10.1-91.el7cf.noarch.rpm
rubygem-power_assert-0.4.1-91.el7cf.noarch.rpm
rubygem-rake-12.0.0-91.el7cf.noarch.rpm
rubygem-rdoc-5.0.0-91.el7cf.noarch.rpm
rubygem-test-unit-3.2.3-91.el7cf.noarch.rpm
rubygem-xmlrpc-0.2.1-91.el7cf.noarch.rpm
rubygems-2.6.14.4-91.el7cf.noarch.rpm
rubygems-devel-2.6.14.4-91.el7cf.noarch.rpm
x86_64:
cfme-5.10.5.1-1.el7cf.x86_64.rpm
cfme-amazon-smartstate-5.10.5.1-1.el7cf.x86_64.rpm
cfme-appliance-5.10.5.1-1.el7cf.x86_64.rpm
cfme-appliance-common-5.10.5.1-1.el7cf.x86_64.rpm
cfme-appliance-debuginfo-5.10.5.1-1.el7cf.x86_64.rpm
cfme-appliance-tools-5.10.5.1-1.el7cf.x86_64.rpm
cfme-debuginfo-5.10.5.1-1.el7cf.x86_64.rpm
cfme-gemset-5.10.5.1-1.el7cf.x86_64.rpm
cfme-gemset-debuginfo-5.10.5.1-1.el7cf.x86_64.rpm
ruby-2.4.6-91.el7cf.x86_64.rpm
ruby-debuginfo-2.4.6-91.el7cf.x86_64.rpm
ruby-devel-2.4.6-91.el7cf.x86_64.rpm
ruby-libs-2.4.6-91.el7cf.x86_64.rpm
rubygem-bigdecimal-1.3.2-91.el7cf.x86_64.rpm
rubygem-did_you_mean-1.1.0-91.el7cf.x86_64.rpm
rubygem-io-console-0.4.6-91.el7cf.x86_64.rpm
rubygem-net-telnet-0.1.1-91.el7cf.x86_64.rpm
rubygem-openssl-2.0.9-91.el7cf.x86_64.rpm
rubygem-psych-2.2.2-91.el7cf.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
An update is now available for CloudForms Management Engine 5.10.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Topic
Relevant Releases Architectures
CloudForms Management Engine 5.10 - noarch, x86_64
Bugs Fixed
1669023 - Network->Providers fails to refresh RHV Provider Network Manager with error Network->Providers fails to refresh RHV Provider Network Manager with error
1692512 - CVE-2019-8320 rubygems: Delete directory using symlink when decompressing tar
1692514 - CVE-2019-8321 rubygems: Escape sequence injection vulnerability in verbose
1692516 - CVE-2019-8322 rubygems: Escape sequence injection vulnerability in gem owner
1692519 - CVE-2019-8323 rubygems: Escape sequence injection vulnerability in API response handling
1692520 - CVE-2019-8324 rubygems: Installing a malicious gem may lead to arbitrary code execution
1692522 - CVE-2019-8325 rubygems: Escape sequence injection vulnerability in errors1703104 - [v2v] [RFE] Enable the Conversion Hosts settings page and wizard in the UI
1710497 - Issues found when modifying roles assigned to buttons
1710578 - Dynamic Field becomes blank on clicking on Refresh button in Service dialog
1710606 - evm.object['value '] can not be used in other field
1710608 - refresh methods are unable to populate textarea fields with yaml content
1710610 - Dialog passing nil value even though value is set
1710998 - Assigned filters don't work if datastore is deleted which has the filter assigned and it shows every cluster regardless of the assignment
1711031 - [v2v] [RFE] Add ability to download Conversion Host enablement playbook log from UI
1711032 - [RFE] Filter out ISO and Export storage domains for RHV Infra Mapping wiizard
1711033 - [v2v] [RFE] Add info popover to VDDK Library Path field in Configure Conversion Host wizard
1711034 - [v2v][RFE] Completed Migration plans cannot be ordered by execution order
1711035 - Extra variables are not passed properly to ansible when configuring conversion host
1711036 - [V2V][OSP] End to end migration not able to proceed with false "no conversion host was configured" error
1711283 - infinispinner on selecting/deselecting search filter in vms/instances view
1711285 - [V2V][OSP] Can not detect if conversion instance is enabled/added on OSP project in infra map
1711957 - [RHV 4.3] IP Address Not Always Being Displayed in CFME
1711981 - Unable to view service tree hierarchy
1712135 - [V2V][RHV][VDDK][SSH] Migration failing with 'rescue in run_conversion' error in automation
1712440 - Cannot create a group after validation message 'Description is not unique'
1712595 - VM Provisioning Timeout - EMS needs manual refresh to see 'new' VMs
1713477 - service bundle retirement requests that hit an error cannot be attempted again due to way the state is handled
1713731 - [V2v][UI] 'Configure' button of authenticate modal from conversion host UI need to be responsive on 'verify TLS' bootstrap switch
1713732 - [V2V][UI] Wrap migration details page's popover appropriately on errors1717500 - After upgrade the dynamically popullated "text area" fields pass null to ansible tower templates.
1717501 - Values from a dialog element populated from a dynamic method are not always passed to service or button method.