Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Red Hat Virtualization 4.4 Update - RHSA-2020:3807-01 Moderate Fixes

red hat
Calendar Grey September 23, 2020
Dist Redhat Esm H88
Red Hat's security advisory for its Virtualization Engine addresses moderate vulnerabilities, urging users to apply critical updates promptly for optimal security.
An update is now available for Red Hat Virtualization Engine 4.4

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/2974891

Summary

The org.ovirt.engine-root is a core component of oVirt.
The following packages have been upgraded to a later upstream version: ansible-runner-service (1.0.5), org.ovirt.engine-root (4.4.2.3), ovirt-engine-dwh (4.4.2.1), ovirt-engine-extension-aaa-ldap (1.4.1), ovirt-engine-ui-extensions (1.2.3), ovirt-log-collector (4.4.3), ovirt-web-ui (1.6.4), rhvm-branding-rhv (4.4.5), rhvm-dependencies (4.4.1), vdsm-jsonrpc-java (1.5.5). (BZ#1674420, BZ#1866734)
A list of bugs fixed in this update is available in the Technical Notes book:
ml-single/technical_notes
Security Fix(es):
* nodejs-lodash: prototype pollution in zipObjectDeep function (CVE-2020-8203)
* jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)
* jQuery: passing HTML containing

References

https://access.redhat.com/security/cve/CVE-2020-8203 https://access.redhat.com/security/cve/CVE-2020-11022 https://access.redhat.com/security/cve/CVE-2020-11023 https://access.redhat.com/security/cve/CVE-2020-14333 https://access.redhat.com/security/updates/classification#moderate

Package List

RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4:
Source: ansible-runner-service-1.0.5-1.el8ev.src.rpm ovirt-engine-4.4.2.3-0.6.el8ev.src.rpm ovirt-engine-dwh-4.4.2.1-1.el8ev.src.rpm ovirt-engine-extension-aaa-ldap-1.4.1-1.el8ev.src.rpm ovirt-engine-ui-extensions-1.2.3-1.el8ev.src.rpm ovirt-log-collector-4.4.3-1.el8ev.src.rpm ovirt-web-ui-1.6.4-1.el8ev.src.rpm rhvm-branding-rhv-4.4.5-1.el8ev.src.rpm rhvm-dependencies-4.4.1-1.el8ev.src.rpm vdsm-jsonrpc-java-1.5.5-1.el8ev.src.rpm
noarch: ansible-runner-service-1.0.5-1.el8ev.noarch.rpm ovirt-engine-4.4.2.3-0.6.el8ev.noarch.rpm ovirt-engine-backend-4.4.2.3-0.6.el8ev.noarch.rpm ovirt-engine-dbscripts-4.4.2.3-0.6.el8ev.noarch.rpm ovirt-engine-dwh-4.4.2.1-1.el8ev.noarch.rpm ovirt-engine-dwh-grafana-integration-setup-4.4.2.1-1.el8ev.noarch.rpm ovirt-engine-dwh-setup-4.4.2.1-1.el8ev.noarch.rpm ovirt-engine-extension-aaa-ldap-1.4.1-1.el8ev.noarch.rpm ovirt-engine-extension-aaa-ldap-setup-1.4.1-1.el8ev.noarch.rpm ovirt-engine-health-check-bundler-4.4.2.3-0.6.el8ev.noarch.rpm ovirt-engine-restapi-4.4.2.3-0.6.el8ev.noarch.rpm ovirt-engine-setup-4.4.2.3-0.6.el8ev.noarch.rpm ovirt-engine-setup-base-4.4.2.3-0.6.el8ev.noarch.rpm ovirt-engine-setup-plugin-cinderlib-4.4.2.3-0.6.el8ev.noarch.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2020:3807-01
Product: Red Hat Virtualization
Issue date: 2020-09-23

Topic

An update is now available for Red Hat Virtualization Engine 4.4.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4 - noarch

Bugs Fixed

1625499 - Cannot assign direct LUN from FC storage - grayed out

1638217 - VM portal always asks how to open console.vv even it has been set to default application.

1643520 - RESTAPI Not able to remove the QoS from a disk profile

1674420 - [RFE] - add support for Cascadelake-Server CPUs (and IvyBridge)

1748879 - On OVA import, qemu-img fails to write to NFS storage domain

1749803 - [RFE] Improve workflow for storage migration of VMs with multiple disks

1758024 - Long running Ansible tasks timeout and abort for RHV-H hosts with STIG/Security Profiles applied

1763812 - [RFE] Move the Remove VM button to the drop down menu when viewing details such as snapshots

1778471 - Using more than one asterisk in LDAP search string is not working when searching for AD users.

1787854 - RHV: Updating/reinstall a host which is part of affinity labels is removed from the affinity label.

1801206 - Possible missing block path for a SCSI host device needs to be handled in the UI

1803856 - [Scale] ovirt-vmconsole takes too long or times out in a 500+ VM environment.

1804037 - Scheduling Memory calculation disregards huge-pages

1804046 - Engine does not reduce scheduling memory when a VM with dynamic hugepages runs.

1806339 - In Admin Portal, "Huge Pages (size: amount)" needs to be clarified

1816951 - [CNV&RHV] CNV VM migration failure is not handled correctly by the engine

1819260 - [RFE] enhance search filter for Storage Domains with free argument

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here