Important: RHV 4.4 SP1 [ovirt-4.5.3-3] security update

Related Vulnerabilities: CVE-2021-30483   CVE-2022-45047  

Synopsis

Important: RHV 4.4 SP1 [ovirt-4.5.3-3] security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated RHV packages that fix several bugs and add various enhancements are now available.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning.

Security fix(es):

  • mina-sshd: Java unsafe deserialization vulnerability (CVE-2022-45047)
  • isomorphic-git: Directory traversal via a crafted repository (CVE-2021-30483)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • With this release, SELinux rules for the Grafana HTTP port are now properly set up for new remote DWH installations as part of the Red Hat Virtualization Manager engine-setup. (BZ#2126778)
  • Previously, search conditions were not applied properly when a non-admin user tried to search for Clusters or Data Centers over the REST API. In this release, both admin and non-admin users can search for clusters properly using the REST API. (BZ#2144346)
  • Previously, stale bitmaps in the base image during a cold or live internal merge caused the operation to fail. In this release, the merge operation succeeds. (BZ#2141371)

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/2974891

Affected Products

  • Red Hat Virtualization Manager 4.4 x86_64
  • Red Hat Virtualization 4 for RHEL 8 x86_64
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64
  • Red Hat Virtualization for IBM Power LE 4 for RHEL 8 ppc64le

Fixes

  • BZ - 1988539 - CVE-2021-30483 isomorphic-git: Directory traversal via a crafted repository
  • BZ - 2126778 - Port 3000 blocked between engine and remote DWH with Grafana
  • BZ - 2141371 - Incorrect image chain when deleting an intermediate snapshot
  • BZ - 2144346 - Search returns all entities the permissions allow if the user is not admin
  • BZ - 2145194 - CVE-2022-45047 mina-sshd: Java unsafe deserialization vulnerability
  • BZ - 2152015 - Discrepancy tool fails with KeyError
  • BZ - 2152845 - Storage stabilization for 4.5.3