First published: Thu May 26 2022(Updated: )
The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning.<br>Security Fix(es):<br><li> nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)</li> <li> nodejs-trim-off-newlines: ReDoS via string processing (CVE-2021-23425)</li> <li> normalize-url: ReDoS for data URLs (CVE-2021-33502)</li> <li> jquery-ui: XSS in the altField option of the datepicker widget (CVE-2021-41182)</li> <li> jquery-ui: XSS in *Text options of the datepicker widget (CVE-2021-41183)</li> <li> jquery-ui: XSS in the 'of' option of the .position() util (CVE-2021-41184)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>A list of bugs fixed in this update is available in the Technical Notes book:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_virtualization/4.4/html-single/technical_notes" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_virtualization/4.4/html-single/technical_notes</a>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible-runner | <2.1.3-1.el8e | 2.1.3-1.el8e |
redhat/apache-sshd | <2.8.0-0.1.el8e | 2.8.0-0.1.el8e |
redhat/engine-db-query | <1.6.4-1.el8e | 1.6.4-1.el8e |
redhat/ovirt-dependencies | <4.5.1-1.el8e | 4.5.1-1.el8e |
redhat/ovirt-engine | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-dwh | <4.5.2-1.el8e | 4.5.2-1.el8e |
redhat/ovirt-engine-metrics | <1.6.0-1.el8e | 1.6.0-1.el8e |
redhat/ovirt-engine-ui-extensions | <1.3.3-1.el8e | 1.3.3-1.el8e |
redhat/ovirt-log-collector | <4.4.5-1.el8e | 4.4.5-1.el8e |
redhat/ovirt-web-ui | <1.8.1-2.el8e | 1.8.1-2.el8e |
redhat/rhv-log-collector-analyzer | <1.0.13-1.el8e | 1.0.13-1.el8e |
redhat/rhvm-branding-rhv | <4.4.11-1.el8e | 4.4.11-1.el8e |
redhat/rhvm-setup-plugins | <4.5.0-2.el8e | 4.5.0-2.el8e |
redhat/vdsm-jsonrpc-java | <1.7.1-2.el8e | 1.7.1-2.el8e |
redhat/apache-sshd-javadoc | <2.8.0-0.1.el8e | 2.8.0-0.1.el8e |
redhat/ovirt-engine-backend | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-dbscripts | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-dwh-grafana-integration-setup | <4.5.2-1.el8e | 4.5.2-1.el8e |
redhat/ovirt-engine-dwh-setup | <4.5.2-1.el8e | 4.5.2-1.el8e |
redhat/ovirt-engine-health-check-bundler | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-restapi | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-setup | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-setup-base | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-setup-plugin-cinderlib | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-setup-plugin-imageio | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-setup-plugin-ovirt-engine | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-setup-plugin-ovirt-engine-common | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-setup-plugin-vmconsole-proxy-helper | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-setup-plugin-websocket-proxy | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-tools | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-tools-backup | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-vmconsole-proxy-helper | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-webadmin-portal | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/ovirt-engine-websocket-proxy | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/python3-ovirt-engine-lib | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/python38-ansible-runner | <2.1.3-1.el8e | 2.1.3-1.el8e |
redhat/python38-docutils | <0.14-12.4.el8e | 0.14-12.4.el8e |
redhat/rhvm | <4.5.0.7-0.9.el8e | 4.5.0.7-0.9.el8e |
redhat/vdsm-jsonrpc-java-javadoc | <1.7.1-2.el8e | 1.7.1-2.el8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.