First published: Tue Feb 02 2021(Updated: )
The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning.<br>The Manager is a JBoss Application Server application that provides several interfaces through which the virtual environment can be accessed and interacted with, including an Administration Portal, a VM Portal, and a Representational State Transfer (REST) Application Programming Interface (API).<br>Security Fix(es):<br><li> jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) (CVE-2020-25649)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Red Hat Virtualization Manager now requires Ansible 2.9.15. (BZ#1901946)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ovirt-engine | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-dwh | <4.4.4.2-1.el8e | 4.4.4.2-1.el8e |
redhat/ovirt-web-ui | <1.6.6-1.el8e | 1.6.6-1.el8e |
redhat/rhv-log-collector-analyzer | <1.0.6-1.el8e | 1.0.6-1.el8e |
redhat/rhvm-branding-rhv | <4.4.7-1.el8e | 4.4.7-1.el8e |
redhat/vdsm-jsonrpc-java | <1.6.0-1.el8e | 1.6.0-1.el8e |
redhat/ovirt-engine-backend | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-dbscripts | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-dwh-grafana-integration-setup | <4.4.4.2-1.el8e | 4.4.4.2-1.el8e |
redhat/ovirt-engine-dwh-setup | <4.4.4.2-1.el8e | 4.4.4.2-1.el8e |
redhat/ovirt-engine-health-check-bundler | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-restapi | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-setup | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-setup-base | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-setup-plugin-cinderlib | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-setup-plugin-imageio | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-setup-plugin-ovirt-engine | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-setup-plugin-ovirt-engine-common | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-setup-plugin-vmconsole-proxy-helper | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-setup-plugin-websocket-proxy | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-tools | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-tools-backup | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-vmconsole-proxy-helper | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-webadmin-portal | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/ovirt-engine-websocket-proxy | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/python3-ovirt-engine-lib | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
redhat/rhvm | <4.4.4.5-0.10.el8e | 4.4.4.5-0.10.el8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.