Important: CloudForms 4.7.5 security, bug fix and enhancement update

Synopsis

Important: CloudForms 4.7.5 security, bug fix and enhancement update

Type/Severity

Security Advisory: Important

Topic

An update is now available for CloudForms Management Engine 5.10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324)
  • rubygems: Delete directory using symlink when decompressing tar (CVE-2019-8320)
  • rubygems: Escape sequence injection vulnerability in verbose (CVE-2019-8321)
  • rubygems: Escape sequence injection vulnerability in gem owner (CVE-2019-8322)
  • rubygems: Escape sequence injection vulnerability in API response handling (CVE-2019-8323)
  • rubygems: Escape sequence injection vulnerability in errors (CVE-2019-8325)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

If the postgresql service is running, it will be automatically restarted after installing this update. After installing the updated packages, the httpd daemon will be restarted automatically.

Affected Products

  • Red Hat CloudForms 4.7 x86_64

Fixes

  • BZ - 1669023 - Network->Providers fails to refresh RHV Provider Network Manager with error Network->Providers fails to refresh RHV Provider Network Manager with error
  • BZ - 1692512 - CVE-2019-8320 rubygems: Delete directory using symlink when decompressing tar
  • BZ - 1692514 - CVE-2019-8321 rubygems: Escape sequence injection vulnerability in verbose
  • BZ - 1692516 - CVE-2019-8322 rubygems: Escape sequence injection vulnerability in gem owner
  • BZ - 1692519 - CVE-2019-8323 rubygems: Escape sequence injection vulnerability in API response handling
  • BZ - 1692520 - CVE-2019-8324 rubygems: Installing a malicious gem may lead to arbitrary code execution
  • BZ - 1692522 - CVE-2019-8325 rubygems: Escape sequence injection vulnerability in errors
  • BZ - 1703104 - [v2v] [RFE] Enable the Conversion Hosts settings page and wizard in the UI
  • BZ - 1710497 - Issues found when modifying roles assigned to buttons
  • BZ - 1710578 - Dynamic Field becomes blank on clicking on Refresh button in Service dialog
  • BZ - 1710606 - evm.object['value '] can not be used in other field
  • BZ - 1710608 - refresh methods are unable to populate textarea fields with yaml content
  • BZ - 1710610 - Dialog passing nil value even though value is set
  • BZ - 1710998 - Assigned filters don't work if datastore is deleted which has the filter assigned and it shows every cluster regardless of the assignment
  • BZ - 1711031 - [v2v] [RFE] Add ability to download Conversion Host enablement playbook log from UI
  • BZ - 1711032 - [RFE] Filter out ISO and Export storage domains for RHV Infra Mapping wiizard
  • BZ - 1711033 - [v2v] [RFE] Add info popover to VDDK Library Path field in Configure Conversion Host wizard
  • BZ - 1711034 - [v2v][RFE] Completed Migration plans cannot be ordered by execution order
  • BZ - 1711035 - Extra variables are not passed properly to ansible when configuring conversion host
  • BZ - 1711036 - [V2V][OSP] End to end migration not able to proceed with false "no conversion host was configured" error
  • BZ - 1711283 - infinispinner on selecting/deselecting search filter in vms/instances view
  • BZ - 1711285 - [V2V][OSP] Can not detect if conversion instance is enabled/added on OSP project in infra map
  • BZ - 1711957 - [RHV 4.3] IP Address Not Always Being Displayed in CFME
  • BZ - 1711981 - Unable to view service tree hierarchy
  • BZ - 1712135 - [V2V][RHV][VDDK][SSH] Migration failing with 'rescue in run_conversion' error in automation
  • BZ - 1712440 - Cannot create a group after validation message 'Description is not unique'
  • BZ - 1712595 - VM Provisioning Timeout - EMS needs manual refresh to see 'new' VMs
  • BZ - 1713477 - service bundle retirement requests that hit an error cannot be attempted again due to way the state is handled
  • BZ - 1713731 - [V2v][UI] 'Configure' button of authenticate modal from conversion host UI need to be responsive on 'verify TLS' bootstrap switch
  • BZ - 1713732 - [V2V][UI] Wrap migration details page's popover appropriately on errors
  • BZ - 1717500 - After upgrade the dynamically popullated "text area" fields pass null to ansible tower templates.
  • BZ - 1717501 - Values from a dialog element populated from a dynamic method are not always passed to service or button method.

CVEs

References