First published: Thu Oct 10 2019(Updated: )
The ovirt-engine-ui-extensions package contains UI plugins that provide various extensions to the oVirt administration UI.<br>Security Fix(es):<br><li> bootstrap: XSS in the data-target attribute (CVE-2016-10735)</li> <li> bootstrap: XSS in the tooltip data-viewport attribute (CVE-2018-20676)</li> <li> bootstrap: XSS in the affix configuration target property (CVE-2018-20677)</li> <li> bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)</li> <li> js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection (CVE-2019-11358)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Known moderate severity security vulnerability detected by GitHub on ovirt-engine-ui-extensions components (BZ#1694035)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ovirt-engine-ui-extensions | <1.0.10-1.el7e | 1.0.10-1.el7e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.