Advisory Published

RHSA-2020:3807: Moderate: Red Hat Virtualization security, bug fix, and enhancement update

First published: Wed Sep 23 2020(Updated: )

The org.ovirt.engine-root is a core component of oVirt.<br>The following packages have been upgraded to a later upstream version: ansible-runner-service (1.0.5), org.ovirt.engine-root (4.4.2.3), ovirt-engine-dwh (4.4.2.1), ovirt-engine-extension-aaa-ldap (1.4.1), ovirt-engine-ui-extensions (1.2.3), ovirt-log-collector (4.4.3), ovirt-web-ui (1.6.4), rhvm-branding-rhv (4.4.5), rhvm-dependencies (4.4.1), vdsm-jsonrpc-java (1.5.5). (BZ#1674420, BZ#1866734)<br>A list of bugs fixed in this update is available in the Technical Notes<br>book:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_virtualization/4.4/html-single/technical_notes" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_virtualization/4.4/html-single/technical_notes</a> Security Fix(es):<br><li> nodejs-lodash: prototype pollution in zipObjectDeep function (CVE-2020-8203)</li> <li> jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)</li> <li> jQuery: passing HTML containing &lt;option&gt; elements to manipulation methods could result in untrusted code execution (CVE-2020-11023)</li> <li> ovirt-engine: Reflected cross site scripting vulnerability (CVE-2020-14333)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Cannot assign direct LUN from FC storage - grayed out (BZ#1625499)</li> <li> VM portal always asks how to open console.vv even it has been set to default application. (BZ#1638217)</li> <li> RESTAPI Not able to remove the QoS from a disk profile (BZ#1643520)</li> <li> On OVA import, qemu-img fails to write to NFS storage domain (BZ#1748879)</li> <li> Possible missing block path for a SCSI host device needs to be handled in the UI (BZ#1801206)</li> <li> Scheduling Memory calculation disregards huge-pages (BZ#1804037)</li> <li> Engine does not reduce scheduling memory when a VM with dynamic hugepages runs. (BZ#1804046)</li> <li> In Admin Portal, "Huge Pages (size: amount)" needs to be clarified (BZ#1806339)</li> <li> Refresh LUN is using host from different Data Center to scan the LUN (BZ#1838051)</li> <li> Unable to create Windows VM's with Mozilla Firefox version 74.0.1 and greater for RHV-M GUI/Webadmin portal (BZ#1843234)</li> <li> [RHV-CNV] - NPE when creating new VM in cnv cluster (BZ#1854488)</li> <li> [CNV&amp;RHV] Add-Disk operation failed to complete. (BZ#1855377)</li> <li> Cannot create KubeVirt VM as a normal user (BZ#1859460)</li> <li> Welcome page - remove Metrics Store links and update "Insights Guide" link (BZ#1866466)</li> <li> [RHV 4.4] Change in CPU model name after RHVH upgrade (BZ#1869209)</li> <li> VM vm-name is down with error. Exit message: unsupported configuration: Can't add USB input device. USB bus is disabled. (BZ#1871235)</li> <li> spec_ctrl host feature not detected (BZ#1875609)</li> Enhancement(s):<br><li> [RFE] API for changed blocks/sectors for a disk for incremental backup usage (BZ#1139877)</li> <li> [RFE] Improve workflow for storage migration of VMs with multiple disks (BZ#1749803)</li> <li> [RFE] Move the Remove VM button to the drop down menu when viewing details such as snapshots (BZ#1763812)</li> <li> [RFE] enhance search filter for Storage Domains with free argument (BZ#1819260)</li>

Affected SoftwareAffected VersionHow to fix
redhat/ansible-runner-service<1.0.5-1.el8e
1.0.5-1.el8e
redhat/ovirt-engine<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-dwh<4.4.2.1-1.el8e
4.4.2.1-1.el8e
redhat/ovirt-engine-extension-aaa-ldap<1.4.1-1.el8e
1.4.1-1.el8e
redhat/ovirt-engine-ui-extensions<1.2.3-1.el8e
1.2.3-1.el8e
redhat/ovirt-log-collector<4.4.3-1.el8e
4.4.3-1.el8e
redhat/ovirt-web-ui<1.6.4-1.el8e
1.6.4-1.el8e
redhat/rhvm-branding-rhv<4.4.5-1.el8e
4.4.5-1.el8e
redhat/rhvm-dependencies<4.4.1-1.el8e
4.4.1-1.el8e
redhat/vdsm-jsonrpc-java<1.5.5-1.el8e
1.5.5-1.el8e
redhat/ovirt-engine-backend<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-dbscripts<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-dwh-grafana-integration-setup<4.4.2.1-1.el8e
4.4.2.1-1.el8e
redhat/ovirt-engine-dwh-setup<4.4.2.1-1.el8e
4.4.2.1-1.el8e
redhat/ovirt-engine-extension-aaa-ldap-setup<1.4.1-1.el8e
1.4.1-1.el8e
redhat/ovirt-engine-health-check-bundler<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-restapi<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-setup<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-setup-base<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-setup-plugin-cinderlib<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-setup-plugin-imageio<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-setup-plugin-ovirt-engine<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-setup-plugin-ovirt-engine-common<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-setup-plugin-vmconsole-proxy-helper<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-setup-plugin-websocket-proxy<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-tools<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-tools-backup<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-vmconsole-proxy-helper<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-webadmin-portal<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/ovirt-engine-websocket-proxy<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/python3-ovirt-engine-lib<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e
redhat/rhvm<4.4.2.3-0.6.el8e
4.4.2.3-0.6.el8e

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203