First published: Wed Jan 11 2023(Updated: )
The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning.<br>Security fix(es):<br><li> mina-sshd: Java unsafe deserialization vulnerability (CVE-2022-45047)</li> <li> isomorphic-git: Directory traversal via a crafted repository (CVE-2021-30483)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> With this release, SELinux rules for the Grafana HTTP port are now properly set up for new remote DWH installations as part of the Red Hat Virtualization Manager engine-setup. (BZ#2126778)</li> <li> Previously, search conditions were not applied properly when a non-admin user tried to search for Clusters or Data Centers over the REST API. In this release, both admin and non-admin users can search for clusters properly using the REST API. (BZ#2144346)</li> <li> Previously, stale bitmaps in the base image during a cold or live internal merge caused the operation to fail. In this release, the merge operation succeeds. (BZ#2141371)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/apache-sshd | <2.9.2-0.1.el8e | 2.9.2-0.1.el8e |
redhat/ovirt-engine | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-ui-extensions | <1.3.7-1.el8e | 1.3.7-1.el8e |
redhat/ovirt-web-ui | <1.9.3-1.el8e | 1.9.3-1.el8e |
redhat/rhv-log-collector-analyzer | <1.0.16-1.el8e | 1.0.16-1.el8e |
redhat/apache-sshd-javadoc | <2.9.2-0.1.el8e | 2.9.2-0.1.el8e |
redhat/ovirt-engine-backend | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-dbscripts | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-health-check-bundler | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-restapi | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-setup | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-setup-base | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-setup-plugin-cinderlib | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-setup-plugin-imageio | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-setup-plugin-ovirt-engine | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-setup-plugin-ovirt-engine-common | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-setup-plugin-vmconsole-proxy-helper | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-setup-plugin-websocket-proxy | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-tools | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-tools-backup | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-vmconsole-proxy-helper | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-webadmin-portal | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/ovirt-engine-websocket-proxy | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/python3-ovirt-engine-lib | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/rhvm | <4.5.3.5-1.el8e | 4.5.3.5-1.el8e |
redhat/vdsm | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-api | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-client | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-common | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-gluster | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-checkips | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-cpuflags | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-ethtool-options | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-extra-ipv4-addrs | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-fcoe | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-localdisk | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-nestedvt | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-openstacknet | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-hook-vhostmd | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-http | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-jsonrpc | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-network | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-python | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
redhat/vdsm-yajsonrpc | <4.50.3.6-1.el8e | 4.50.3.6-1.el8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.