Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2018:1328 - Security Advisory
Issued:
2018-05-07
Updated:
2018-05-07

RHSA-2018:1328 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: CloudForms 4.6.2 bug fix and enhancement update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for CloudForms Management Engine 5.9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • python-paramiko: Authentication bypass in transport.py (CVE-2018-7750)
  • ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges (CVE-2018-1101)

Red Hat would like to thank Graham Mainwaring of Red Hat for reporting CVE-2018-1101.

  • ansible-tower: Remote code execution by users with access to define variables in job templates (CVE-2018-1104)

Red Hat would like to thank Simon Vikström for reporting CVE-2018-1104.

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat CloudForms 4.6 x86_64

Fixes

  • BZ - 1495849 - [ALL_LANG] VM or Template comparison screen has untranslated entries.
  • BZ - 1510499 - With RHV Graph refresh template numbers in Provider inventory does not get updated correctly.
  • BZ - 1526086 - [ALL_LANG] Compute - Containers - Container Builds page has missing translations
  • BZ - 1526088 - [ALL_LANG] Compute - Containers - Pods page has missing translations
  • BZ - 1530680 - xClarity: EvmRole-operator unable to view physical server summary page
  • BZ - 1530760 - [ALL_LANG] Control - Explorer - Policy Profiles - All Policy Profiles : 'Policy' is not localized
  • BZ - 1533220 - [ALL_LANG] Control - Explorer - Actions - All Actions - Configure - Add a new Action : 'Action Type' drop-down menu has untranslated entries
  • BZ - 1533233 - On Tag Assignment page Category has other Tags than preconfigured for it
  • BZ - 1533515 - [ALL_LANG] User Icon - Configuration - Access Control - Roles : Add new Role has untranslated entries
  • BZ - 1538094 - [ALL_LANG] User Icon - Tasks : untranslated entry
  • BZ - 1538100 - [ALL_LANG] User Icon - Configuration - Settings - CFME Region: Region xx[xx] has untranslated entry
  • BZ - 1549625 - webui updates failing when a proxy is required
  • BZ - 1549722 - WebUI: Tool tip displays html code while setting the ownership for multiple vm's
  • BZ - 1550728 - Replication configuration page does not open when child database is down
  • BZ - 1550730 - [Ansible Embedded] - Embedded Ansible cannot be enabled on IPv6 only appliance
  • BZ - 1550736 - unable to view quotas without manage quota permissoin being enabled in 5.8.2
  • BZ - 1551692 - internal server error ActiveRecord::AssociationTypeMismatch when editing current_group
  • BZ - 1551696 - Colons are unhandled in BaseModel key generation in AzureArmrest
  • BZ - 1551698 - Not possible to configure GCE provider for new regions (southamerica-east1) on CFME
  • BZ - 1551703 - RHOS: Unable to delete cloud tenant
  • BZ - 1552266 - Duplicated choice exist in new alerts view
  • BZ - 1552269 - Network router type string contains ManageIQ path
  • BZ - 1552278 - Authentication issue for checking status of Task API via EvmRole_administrator privileged User
  • BZ - 1552282 - [RFE] Make Automation State Machine Log Lines Uniform
  • BZ - 1552288 - [RFE] Metrics for memory usage of AWS instances is missing from C&U
  • BZ - 1552290 - AWS Smartstate Does Not Fail Gracefully if AMI To run Analysis Agent is Unavailable
  • BZ - 1552301 - Azure Template to service Dialog conversion issue
  • BZ - 1552303 - [Azure]Provision Multiple VMs with Public IP selection options
  • BZ - 1552305 - GCE Region is useless in GCE Provider
  • BZ - 1552323 - xClarity: server-host relationship to hosts managed by RHEV-M provider not created.
  • BZ - 1552334 - Nuage provider name is always displayed as " Network Manager" on GUI
  • BZ - 1552335 - EventCatcher is not restarted when Nuage provider is updated
  • BZ - 1552671 - [RFE][XS-2] Add possibility to unregister a VM in RHV provider
  • BZ - 1552673 - Cloudforms doesn't show IP of vms on vCloud provider
  • BZ - 1552677 - VM does not have deletion event on its own timeline on vsphere55
  • BZ - 1552704 - Default Docker Labels for Labeled Images in Chargeback Assignments
  • BZ - 1552707 - Wrong error displayed when trying to add a group without a name
  • BZ - 1552723 - Can't Manage Report Menu Accordions and Folders
  • BZ - 1552735 - Filters not working properly in config mgmt configured systems
  • BZ - 1552737 - UI: Broken bootstrapswitch design in custom button option of generic object
  • BZ - 1552739 - [RFE] Expose Infra provider networks (RHOS) in host/node details
  • BZ - 1552740 - [ALL_LANG] User Icon - Configuration - Settings - Schedules : Add a new Schedule page has untranslated entries
  • BZ - 1552741 - Can't remove multiple instances or methods in UI.
  • BZ - 1552743 - ui: Tabs switched When changing the System/Process type on add new button page
  • BZ - 1552746 - typo in provider summary page: metrics type Hakular --> Hawkular
  • BZ - 1552748 - [Embedded Ansible] Notification typo
  • BZ - 1552753 - CFME Log lines in Diagnostics are divided into multiple lines
  • BZ - 1552762 - Error when applying a filter in My Services from Adv search
  • BZ - 1552763 - Remove Chargeback Rates field for Metering reports
  • BZ - 1552776 - Auth MIQLDAP AD - miqldap_to_sssd conversion fails for ldap.
  • BZ - 1552782 - Smartstate on Azure Managed Linux Instance returns Unable to mount filesystem. Reason:[XFS::DirectoryDataHeader: Invalid Magic Number 0]
  • BZ - 1552783 - Unable to add playbook repos after webui update
  • BZ - 1552785 - Auth MIQLDAP AD - Users can't log in to console after miqldap_to_sssd conversion
  • BZ - 1552790 - Validating credentials for replication throws error if pglogical schema not created
  • BZ - 1552791 - miqldap_to_sssd help message is incorrect
  • BZ - 1552792 - Auth External Auth SAML - Users with custom groups with special chars can't log in.
  • BZ - 1552794 - A control alert for real time performance of a VM and Instance is not firing
  • BZ - 1552796 - [RFE] Chargeback reports for OpenStack tenants
  • BZ - 1552798 - [Providers] - Instances not linked after provider removal/addition
  • BZ - 1552800 - Retirement requester is not passed down correctly to automate
  • BZ - 1552801 - RBAC doesn't work for notifications
  • BZ - 1552802 - No notification for failed registration
  • BZ - 1552804 - configure_server_settings.rb changes numeric values to strings, causing failures when other code is expecting integers
  • BZ - 1552809 - [RFE] Support RestAPI Primary Collection for Containers (object)
  • BZ - 1552817 - SUI doesn't display costs for SCVMM services
  • BZ - 1552824 - Can Add Duplicate Custom Attributes on OpenShift Provider Via the API
  • BZ - 1552826 - internal server error when cloud_networks, cloud_subnets or security_groups subcolls requested on RHEVM
  • BZ - 1552828 - internal server error when accessing attributes of the "picture" resource
  • BZ - 1552838 - Targeted folder refresh doesn't work on VMware
  • BZ - 1552842 - Customize vApp template prior provisioning (VMware vCloud Provider)
  • BZ - 1552873 - RBAC Users can be removed from all associated groups after the webui shows the error "A User must be assigned to a Group"
  • BZ - 1552879 - Tagging broken in Datastores and My Services page
  • BZ - 1552880 - [RFE] There is no any indication in replication subscription screen for not accessible remote node
  • BZ - 1552882 - The quad-icon tile for an OpenShift provider shows an exclamation mark, but a mouseover shows "Refresh Status: Success"
  • BZ - 1552884 - Cursor on password field instead of username when we enter incorrect login details
  • BZ - 1552886 - Unwanted comma in disk type string for Azure instances
  • BZ - 1552889 - containers: identical volume name for different volumes in different pods is not useful for users (at least not admin)
  • BZ - 1552890 - Tagging: Edit tags page doesn't open for network list items navigated through parent details page
  • BZ - 1552895 - Error updating Nuage provider
  • BZ - 1552900 - Title does not update when searching text in Datastores and other pages
  • BZ - 1552903 - Automate tree in the left pane has duplicates following any copy operation (instance, class, namespace)
  • BZ - 1552904 - The accordion folds after adding a schedule
  • BZ - 1552908 - Add button is not responsive on Role add page
  • BZ - 1553191 - Timelines: Throws an error while trying to access Cloud Intel/Timelines
  • BZ - 1553197 - Configuration -> Red Hat Updates tab does not list all required repositories
  • BZ - 1553214 - JavaScript-UI: Wrong behavior of `display on button` checkbox while editing custom group form
  • BZ - 1553224 - Set Ownership can not be changed back to default
  • BZ - 1553241 - Container add provider empty flash message when not catch UI exception
  • BZ - 1553242 - Tag: All Catalog Items are listed in resource dropdown while creating Catalog Bundle using restricted user
  • BZ - 1553243 - Save button isn't activated when date is removed in VM "Set/Remove retirement date"
  • BZ - 1553244 - [QEDevCollab] Components in 'Add button group' form causing test automation failures
  • BZ - 1553251 - Chargeback Rates page title incorrect after deleting rate
  • BZ - 1553288 - Flash message icon is not correct Bottlenecks page
  • BZ - 1553295 - Unable to perform SSA if Vm storage is fileshare on SCVMM and throws error in evm.log
  • BZ - 1553304 - Evacuate Host failed
  • BZ - 1553307 - Undefined method `vmm_version' for nil:NilClass on VM summary screen
  • BZ - 1553309 - [RFE] Generic objects not displayed
  • BZ - 1553311 - Wrong 'Fixed IPs' font size while adding a router with external gateway
  • BZ - 1553315 - C & U Collection settings in configuration page improper styling
  • BZ - 1553316 - On schedules pages is shown pagination from analysis profiles
  • BZ - 1553317 - Broken footer in alerts
  • BZ - 1553319 - [RFE][S-3] UI displays disabled domains for a instance's domain priority
  • BZ - 1553322 - audit.log should not contain translated messages
  • BZ - 1553323 - Adding Interface to Router with user in Tenant show all Subnets and not only the Tenant's Subnet
  • BZ - 1553326 - Switch icon is missed on tag assignment page
  • BZ - 1553327 - Stack Outputs icon is not displayed
  • BZ - 1553329 - Using webmks console one cannot type correctly the password when it contains special characters
  • BZ - 1553336 - Default view settings fails for service catalogs
  • BZ - 1553340 - [CONDITION] When we leave description blank, there are two identical flash messages.
  • BZ - 1553345 - Openstack infra provider dashboard should not appear for an openstack infra provider
  • BZ - 1553362 - Add miqssh utilities
  • BZ - 1553384 - [RHV] VM Reconfigure: Down VM Memory increase fail on cannot exceed maximum memory
  • BZ - 1553389 - VMware vCloud Provider's VM is only partially stopped/suspended
  • BZ - 1553392 - EvmRole-auditor can perform actions on VM
  • BZ - 1553393 - [RFE] Add RBAC and Tagging Support to Ansible Credentials.
  • BZ - 1553396 - [RFE] Add RBAC and Tagging Support to Ansible Repos
  • BZ - 1553397 - Error while checking that migrations are up to date
  • BZ - 1553399 - Normalize text for operational alerts
  • BZ - 1553480 - SUI : Clicking any link on dashboard does not change the navigation in left side
  • BZ - 1553482 - Kebab menu appearing differently on service page and resource detail pages
  • BZ - 1553483 - Kebab menu changes structure after 30 seconds in SSUI resource detail page
  • BZ - 1553768 - [RFE] Add RBAC and Tagging Support to Ansible Playbooks
  • BZ - 1553776 - Role inconsistency with privileges when creating reports and setting chargeback filters
  • BZ - 1553779 - Restricted user can see all group and users
  • BZ - 1553780 - notifications do not get cleared from the notification table
  • BZ - 1553789 - Unable to add tag for configuration provider from 'All Rad Hat Satellites Providers'
  • BZ - 1553791 - xClarity: Physical server summary page download as PDF button not supported
  • BZ - 1553836 - Visibility expression does not evaluated correctly on custom buttons for Generic Object
  • BZ - 1553873 - Missing Datastore Images
  • BZ - 1553903 - [Regression] Backup/restore failing on appliances using pglogical
  • BZ - 1554358 - Graph refresh should not be used for rhv36 providers
  • BZ - 1554370 - Wrong breadcrumb link on order screen
  • BZ - 1554454 - Adding a physical provider shows as infrastructure provider (text change)
  • BZ - 1554532 - Schedule report fails to send mail when report is not empty
  • BZ - 1554541 - Long time to refresh network provider on OpenStack
  • BZ - 1554823 - Infinite spinner on Edit Playbook Reset button
  • BZ - 1554825 - NTP server details doesn't show in UI after adding a new zone
  • BZ - 1554832 - Automatic placement causes cloud tenant to not be selectable
  • BZ - 1554839 - Policy simulation results are not displayed
  • BZ - 1554889 - OpenStack Cinder Storage provider detail does not have link to Volume Backups
  • BZ - 1554898 - when deleting an archived node using configure > remove a unknown method error is raised
  • BZ - 1554901 - Missing Guest OS in dashboard reports in Openstack
  • BZ - 1557130 - CVE-2018-7750 python-paramiko: Authentication bypass in transport.py
  • BZ - 1557353 - Adding a network router via CloudForms the router is not seen by CloudForms
  • BZ - 1557361 - [RFE][XS-2]Cloudforms does not show node hostname, only GUID for OpenStack Infrastructure Provider
  • BZ - 1557367 - Request not required when adding Schedule
  • BZ - 1557378 - [UI] There is no indication of cloud network delete operation
  • BZ - 1557380 - Tagging: Edit tags page doesn't open for images opened from provider summary page
  • BZ - 1557388 - Inconsistent capitalization of 'CPU' when creating chargeback rate
  • BZ - 1557391 - Physical Infrastructure provider quadicons doesn't support single view
  • BZ - 1557400 - Physical server quadicon switch under My Settings doesn't respect RBAC rules
  • BZ - 1558030 - internal server error when accessing the "policy_events" attribute of the "vms" resource
  • BZ - 1558038 - AWS flavor list is out of date
  • BZ - 1558040 - Not able to scan instances in AWS
  • BZ - 1558046 - OpenStack - Include Provider Error Message in MiqProvisionFailure
  • BZ - 1558048 - Provision fails if no Subnet assigned not Cloud Network
  • BZ - 1558078 - [RFE][M-5] Targeted Refresh for Azure Provider
  • BZ - 1558092 - Dropdown to delete a "not responding" server is missing
  • BZ - 1558142 - Network provider quadicons doesn't support single view
  • BZ - 1558144 - UI inconsistency - Size Unit title missing when adding a new disk
  • BZ - 1558544 - Creating buttons under the Datastore objects do not appear on Datastore Details Pages
  • BZ - 1558594 - No event AWS_EC2_Instance_UPDATE when renaming a VM on EC2
  • BZ - 1558610 - Images from the webmks css causes CSP errors in browser console
  • BZ - 1558621 - RedHat domain can be edited/deleted
  • BZ - 1558626 - PG::InvalidTableDefinition: ERROR: cannot alter inherited column "resource_type
  • BZ - 1559475 - CUI returning empty array when dialog without associations is saved
  • BZ - 1559479 - [RFE] Add RHV Credential to Ansible Automation Inside
  • BZ - 1559483 - CUI doesn't check dialog field associations
  • BZ - 1559543 - [RFE] Metering Reports should provide Hours of Existence & Start and end time of VMs, Projects and Images
  • BZ - 1559544 - [RFE] Collect Container Project Quota Historical data in Project Roll-up
  • BZ - 1559550 - Regression Instance Method check_quota Throws Error 5.8.2 to 5.8.3 undefined method provisioned_storage
  • BZ - 1559552 - Api::ServiceCatalogsController timeout error in multi-regional environment
  • BZ - 1559609 - Amazon agent deployment has to choose the VPC which has attached gateway configuration
  • BZ - 1559624 - Graph refresh does not fetch custom attributes
  • BZ - 1560004 - [RFE] SCVMM provider refresh error message issue if provider user doesn't have access to VMM service
  • BZ - 1560096 - Error occurs when trying to edit a catalog item
  • BZ - 1560098 - Outgoing SMTP E-mail Server settings not saved on first attempt
  • BZ - 1560100 - Total matches of Ems Cluster roles showing wrong count
  • BZ - 1560104 - Automate Schedule: "Starting time" field saves nonsense.
  • BZ - 1560692 - Stop CF pestering OpenStack for Swift status when there is no Swift.
  • BZ - 1560699 - Consolidated RefreshWorkers may cause job starvation
  • BZ - 1560703 - Refresh is broken for ec2 when get_public_images is set to true
  • BZ - 1560708 - My Company(All EVM Groups) filter missing from reports schedule
  • BZ - 1561076 - Duplicate RBAC Role and Group names allowed when using different capitalization from the original name
  • BZ - 1561079 - [Regression]Error with report policy event for the last 7 days
  • BZ - 1561085 - [RFE] Azure Network router not displayed on CFMe
  • BZ - 1561091 - List view displayed instead of grid on Manage Policies screen
  • BZ - 1561096 - Default selected tag name / value mismatch when assigning tags
  • BZ - 1561107 - ERROR -- : AnsibleTowerClient::Middleware::RaiseTowerError Response Body: {"detail"=>["'username' is not a valid field for Vault"]}
  • BZ - 1561216 - Failure to refresh on OpenStack provider when Fog::Storage::OpenStack::File object has nil body attribute
  • BZ - 1561218 - [RHV] PXE provision with Network "use template nics" fail on creating VM
  • BZ - 1561222 - ping feature inconsistent with webui ping when database connectivity is lost
  • BZ - 1562075 - Duplicate values are shown in dialog dropdown.
  • BZ - 1562235 - Nics are Provisioned out of Order for VMware Service Provision
  • BZ - 1562772 - tenant source_id compromisation after changing provider credentials
  • BZ - 1562777 - Approval permissions are not followed between different groups
  • BZ - 1562779 - Cannot create service template using the API
  • BZ - 1562780 - [SCVMM]Extract Running Processes completed Task List does not inform about Warnings.
  • BZ - 1562782 - A state machine's on_exit method runs before the main method if the main method is an embedded Ansible playbook
  • BZ - 1562785 - Refresh failed after performing vm_reconfiguration_task
  • BZ - 1562788 - [Regression] RHV provider discovery doesn't work
  • BZ - 1562791 - Database Replication broken for current and new regions
  • BZ - 1562797 - CFME - usage of non standard special characters (e.g. accents) in password causes user is not able to login
  • BZ - 1562800 - Schedule Operation: Cannot create schedule, "Add" button is not active
  • BZ - 1562803 - [RFE] CFME, add Ansible GIT repository custom SSH port option
  • BZ - 1562811 - No Advanced Search in Volume Snapshots/Backups
  • BZ - 1563268 - CloudForms appliance is ignoring azure proxy settings in advanced tab.
  • BZ - 1563351 - Nuage provider is unable to refresh inventory when subnets are missing gateway address
  • BZ - 1563358 - Nuage Networks provider does not handle empty AMQP details
  • BZ - 1563359 - Nuage Provider doesn't capture Alarms
  • BZ - 1563361 - Nuage provider's event catcher yields "Too many open files" after 9 hours
  • BZ - 1563363 - VMware vCloud Provider's inventoring fails because of bug in Disk parsing
  • BZ - 1563364 - Support console access for VMware vCloud Provider's VMs
  • BZ - 1563492 - CVE-2018-1101 ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges
  • BZ - 1563731 - in the conditions screen you see "Container Node" on the left but "Node" on the right
  • BZ - 1563740 - ReconfigVM Event triggers a refresh_sync Holding Automate Process in State Machine
  • BZ - 1565139 - Some expression method definitions can fail with "<Script error>" in a dialog and a stack trace in evm.log
  • BZ - 1565140 - Embedded Ansible job_status .out files are not processed by logrotate
  • BZ - 1565142 - Nuage Provider uses qpid_proton gem version without heartbeating
  • BZ - 1565147 - Unable to create Cloud Network due to undefined method
  • BZ - 1565148 - Service gets submitted even if dialog does not passes validation
  • BZ - 1565151 - Regression Custom Button Dialog Not Displaying Submit or Cancel Button
  • BZ - 1565156 - Unable to see realtime data from OpenShift in CloudForms UI
  • BZ - 1565160 - Ansible playbook credentials always show default value in SUI
  • BZ - 1565167 - openstack provisioning instance fail on checkprovisioned
  • BZ - 1565232 - OpenStack with bad credentials shows timeout
  • BZ - 1565677 - Container reports take too much time to generate
  • BZ - 1565686 - VMware vCloud Provider credential validation fails
  • BZ - 1565756 - Remove specific EVM server from zone
  • BZ - 1565862 - CVE-2018-1104 ansible-tower: Remote code execution by users with access to define variables in job templates
  • BZ - 1566255 - DRb 'close' error for closed connection
  • BZ - 1566526 - Reporting worker exceeding threshold for default report tied to custom widget
  • BZ - 1566529 - Smartstate Analysis Schedule Fails for OpenShift 3.7 Container Images
  • BZ - 1566530 - Report for Storage Capacity Field Generating Error Cannot Convert Hash to Float
  • BZ - 1566541 - [RFE] Target Refresh support for OpenStack Block Storage Manager
  • BZ - 1566557 - [Regression] Infra provider discovery doesn't work
  • BZ - 1566562 - RHSM failing to register with proxy settings
  • BZ - 1566563 - Cloudforms present blank page for backup volumes
  • BZ - 1566568 - Appliances Missing from Global Region are showing a Zone ID of a Local Region
  • BZ - 1566572 - ERROR ASCII-8BIT to UTF-8","klass":"Encoding::UndefinedConversionError"}}
  • BZ - 1566577 - [AZURE]Filter list of available Public IPs
  • BZ - 1566658 - [PRD][RFE] Ansible Next Gen - Playbook Seeding
  • BZ - 1567278 - xClarity: Error while execute the second refresh cycle
  • BZ - 1567962 - VMware vCloud Provider's VMs cannot revert from snapshot
  • BZ - 1568023 - [Embedded Ansible] Standard Output throws error if Hostname has Non-ASCII Characters
  • BZ - 1568091 - Catalog Item with Tag Control element cannot be ordered
  • BZ - 1568156 - Not able to import certain dialogs because of tag Id
  • BZ - 1568158 - User Interface does not come up after reboot
  • BZ - 1568162 - DRO Service mapping to DRO instance incorrect
  • BZ - 1568467 - Cannot put special characters in proxy password in Advanced Config
  • BZ - 1568473 - Saving a service dialog with a multi-select drop-down populated by expression method gives a 500 internal server error
  • BZ - 1568550 - CFME: OpenSCAP evaluation report target machine does not show container image name
  • BZ - 1568559 - Deployment template validation failed
  • BZ - 1568602 - Git repo automate datastore refresh timing out upon credential change
  • BZ - 1569099 - Orphaned and Archived VMs displayed in running vms filter
  • BZ - 1569103 - Online VMs (Powered On) report lists Orphaned and Archived VMs/Instances
  • BZ - 1569113 - Apache Reloaded twice with logrotate
  • BZ - 1569177 - ERROR : 404 when trying to set the retirement date of the service
  • BZ - 1569236 - [UI] - ManageIQ string in PDF summary file for flavors
  • BZ - 1569472 - In dynamic dropdown list, the default value contains ALL the values of the list
  • BZ - 1569551 - Auto-refresh values take forever to load values in dropdown
  • BZ - 1570118 - CloudForms 4.6 - filtering based on tags does not work for catalog items
  • BZ - 1570821 - Unable to run ansible playbook method via Simulate
  • BZ - 1570950 - Service and VM retirement are non-deterministic, running parallel
  • BZ - 1570989 - Service Catalog Item Subtype not rendered in UI
  • BZ - 1571310 - Unable to select storage manager from drop down list through classic UI
  • BZ - 1571976 - Dynamic check box does not update in Classic UI
  • BZ - 1571989 - droplist with large amount of items do not display a search field
  • BZ - 1572711 - Automate Methods from Dynamic Dialog are being Run More than Designed / Expected
  • BZ - 1572716 - Delay in rendering service dialog
  • BZ - 1572718 - Provider Inventory worker vim.log fills up due to large log messages
  • BZ - 1573215 - OpenStack Block Storage Manager Cinder does not refreshed
  • BZ - 1573246 - Workload category for Tag Control element does not work
  • BZ - 1573254 - auto_refresh being used instead of dialog field responders on later versions
  • BZ - 1573539 - Dashboard widget is not providing exact content due to Type conversion Exception.
  • BZ - 1573990 - in certain situations the refresh methods are called on every single refresh

CVEs

  • CVE-2018-1101
  • CVE-2018-1104
  • CVE-2018-7750

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat CloudForms 4.6

SRPM
ansible-2.4.4.0-1.el7ae.src.rpm SHA-256: b08063b8a8b221d7fe97ad47e092aa4d4aeea485c6454c9b91e7fcffe21d78d6
cfme-5.9.2.4-1.el7cf.src.rpm SHA-256: f970f995d81a99b35ed1356b0a80efdbd27398572fdeadb55bb137a613c8c018
cfme-amazon-smartstate-5.9.2.4-1.el7cf.src.rpm SHA-256: a3ecfb23fbbb20231434c2d05b37d778208ff89f0cba2481933b9cdf09f2888a
cfme-appliance-5.9.2.4-1.el7cf.src.rpm SHA-256: 1bb480209f0b9d9c2c28b653848b1784fbf91f1338e65435630e2955552eb796
cfme-gemset-5.9.2.4-1.el7cf.src.rpm SHA-256: 97effe85101fd95f690896b56c37900a8e8ad71714647b4fd4197866e5501ca5
dbus-api-service-1.0.1-3.el7cf.src.rpm SHA-256: 515a4f8dc765aac1ea262cac3b3d077fe889c3e9220917191814a680c43da31e
httpd-configmap-generator-0.2.1-2.el7cf.src.rpm SHA-256: 9d513dcb0bce22d83a26d3ff55c1d0ee84805c18255031f1c1c72cf66f6e06e0
postgresql96-9.6.6-1PGDG.el7.src.rpm SHA-256: dc5f7e4aefc0d355fc58e4ac7191c11664692b0a00e321ca41f33b4f66dfc945
python-paramiko-2.1.1-4.el7.src.rpm SHA-256: 43ba21a7cbfc99918164c9dee8e2c2ece5915b421834a00474d2bfbeb3d748b7
rh-ruby23-rubygem-json-2.1.0-1.el7cf.src.rpm SHA-256: 7eee6c492b240d5ab5b5d61af400a48217e7c858625361f3edef7d373e141260
rh-ruby23-rubygem-qpid_proton-0.22.0-2.el7cf.src.rpm SHA-256: 9d86f00906f69ed8bf8ebef824c75c3e878ebb8fc0dc25041b04a862428a1299
x86_64
ansible-2.4.4.0-1.el7ae.noarch.rpm SHA-256: 04b4ae3d042246fae073db5678490fdd9e88eeb0af36fe3903563bff1e0b24d6
ansible-doc-2.4.4.0-1.el7ae.noarch.rpm SHA-256: 0f60a6c7ad749d994c2a310e09e7fdcdbb5e263bf7911877f3bc0af65435dd9a
ansible-tower-3.2.4-1.el7at.x86_64.rpm SHA-256: ccfa2fc51dd6326501ee102f87b6a456e9e003eb2e71cd754e103a670acc4ae5
ansible-tower-server-3.2.4-1.el7at.x86_64.rpm SHA-256: 126c75b3a81b68eab1b16376f7beb384f5d2e25d8135efd1946f911d9b513b82
ansible-tower-setup-3.2.4-1.el7at.x86_64.rpm SHA-256: c9580547b845e7fbd5f9b6edb6188175970f32758408cc3335ad9cab270fa560
ansible-tower-ui-3.2.4-1.el7at.x86_64.rpm SHA-256: a0e7cf26e216587b6a37aded8a79a9683fc77e1e6f59cfaeb6d2d3a47f2322de
ansible-tower-venv-ansible-3.2.4-1.el7at.x86_64.rpm SHA-256: 81b658afa8ad9093679d5d8f9b8fadaa52b1fd64a760825e9c3476de7ee8b945
ansible-tower-venv-tower-3.2.4-1.el7at.x86_64.rpm SHA-256: 2855377ebfaf4340a527f4133c55a3a03d10c930bff83015986a05c521a18d3a
cfme-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: 205e71a1eef3d68f89e46896aaa8b73273de262d2b39cb0688c7bf7a420034c2
cfme-amazon-smartstate-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: 2a979722f926ddfbbcefa546132098a6cd23ead8fd9b17e3abd823fe26eb7ec4
cfme-appliance-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: f99fcfd164ecf13f6fc58ad5eb83b104a5652ae42af2801845c527f731095c78
cfme-appliance-common-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: e7e764a45c7e5f3ae876f8c512d212484dc24cb82fcb2e1f34382a0ec5a39022
cfme-appliance-debuginfo-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: bf437906adf702a02e1b7b5278ad0d6ecc5ec8d209044b5d9e2fc5f9a8b16e70
cfme-appliance-tools-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: fcd20a99ed5bc06d7c73dcb9f24be15e0c62804632ef045ae03aad32b84b6eed
cfme-debuginfo-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: f95e985d2b04fef378eb34747b8d2896d4f6f091e005b23c184b6ad39035ac58
cfme-gemset-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: 23fc00b78ff66a87ec7374ac7de74d7ea24cb0ec1c7e02c073f44f19591bb0af
cfme-gemset-debuginfo-5.9.2.4-1.el7cf.x86_64.rpm SHA-256: 4557f38e170fc6f8ed33ca8f556a9f0e241b022fade76cb5ef6a92a75906dd3a
dbus-api-service-1.0.1-3.el7cf.x86_64.rpm SHA-256: a6caa5c5ea3253e070d28d7d7b7951c7ab7a439933c81654ca4e897e2f1b74fb
httpd-configmap-generator-0.2.1-2.el7cf.x86_64.rpm SHA-256: f43c1a54746b695f79fe8e295a347622ed1b759555dd3dd5e3e5341727ee166b
postgresql96-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: eb6c9d3562a9cd2518196938aa9b09aa01fb856b6d779b017ed733c793bdb221
postgresql96-contrib-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: ad40440627a76f12c86cbbb109266d66dbd0fd4b65da313b1e7f38b42db7d2c0
postgresql96-debuginfo-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: f11ce70df2a2f6a0037b61140a03adc9cfeb8a73589a9696259cc1e6d5a86d65
postgresql96-devel-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: 0182de8e38da13e2ff91e15bb6ae6f7d3989a81f2c2346c35b2d3a682a8bfece
postgresql96-docs-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: e6f8bd45c26e9697184971d0dc64766c3320f742f804db585a7cda3eb11f5cd9
postgresql96-libs-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: da36e36116a9f1bf650bf14b0569a4824a879ae60c7cc3767a848b13bbd58f54
postgresql96-plperl-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: 90340677cb320c833ae670081f4ca0cbaf9a40269afff94e4fa645be19d48d78
postgresql96-plpython-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: da7a721d52419858592d7fec3eaac7c3d41696351db5758ed1f4b440927aceac
postgresql96-pltcl-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: 01aad242f4999667ad170702335eb2cc1139f2f0d03edac54fc5aca74f3cd62b
postgresql96-server-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: 8c5c5ba7e1d6b6c843ffbee17be1f31c1f07cb0123ba7e32d2bb7616d5fc1374
postgresql96-test-9.6.6-1PGDG.el7.x86_64.rpm SHA-256: 907193abc888b03549f3b09611f9eea1a4bd160cd09facc02699553548cec657
python-paramiko-2.1.1-4.el7.noarch.rpm SHA-256: 461375b1b458818f5b5893aefac09fbf39cd651c081e63479915b8ffa33a72cc
python-paramiko-doc-2.1.1-4.el7.noarch.rpm SHA-256: 4abfc94c371f6fb64761ad9616522bfbab10091dc60cc0513f2496b70a883d36
rh-ruby23-rubygem-json-2.1.0-1.el7cf.x86_64.rpm SHA-256: 0011cff555a196aecca0563ecf27156155d8a4369f7fd155b871bee10d15ad07
rh-ruby23-rubygem-json-debuginfo-2.1.0-1.el7cf.x86_64.rpm SHA-256: 0d0c56ec62c4c2e05114c0a2c33436a61db09514cd3d861048b6aa5e37994f43
rh-ruby23-rubygem-json-doc-2.1.0-1.el7cf.x86_64.rpm SHA-256: be9cf669e54cf32ec4f7dc8c4a00ae34bc408027887e47109f6c04e0b2e2fb23
rh-ruby23-rubygem-qpid_proton-0.22.0-2.el7cf.x86_64.rpm SHA-256: dd382803843587196054d749560abd8a09b879859a10ca8372bf726ba3dc7033
rh-ruby23-rubygem-qpid_proton-debuginfo-0.22.0-2.el7cf.x86_64.rpm SHA-256: 9415b5e4ac4122ac6267bce81f170b6b841dba529de9e05e30e76c932b2204f0
rh-ruby23-rubygem-qpid_proton-doc-0.22.0-2.el7cf.noarch.rpm SHA-256: 5dd8d71645eeacdf787de653e4725d5f092ee9c3087d21be3e9c7ac684746535

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter