Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2019:0315 - Security Advisory
Issued:
2019-02-12
Updated:
2019-02-12

RHSA-2019:0315 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: CloudForms 4.6.8 security, bug fix and enhancement update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for CloudForms Management Engine 5.9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • rubygem-sinatra: XSS in the 400 Bad Request page (CVE-2018-11627)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

If the postgresql service is running, it will be automatically restarted after installing this update. After installing the updated packages, the httpd daemon will be restarted automatically.

Affected Products

  • Red Hat CloudForms 4.6 x86_64

Fixes

  • BZ - 1585218 - CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page
  • BZ - 1641669 - 404 Not Found: When dialog submitted via custom button from datastore object with method and dialog both attached
  • BZ - 1641812 - Retirement Requester not populated after retirement
  • BZ - 1650152 - [RFE] Unable to use AWS tags as RHV tags
  • BZ - 1658480 - Instance evacuation error
  • BZ - 1665284 - Tagging: Unable to edit tag from container provider page
  • BZ - 1667948 - Dynamic drop down code is being executed everytime a service request is opened for review and executed again on approval
  • BZ - 1668847 - Events from OpenStack are delivered in wrong order which causes miss of certain events
  • BZ - 1669627 - SmartState Analysis fails on VMware Vsphere 6.7
  • BZ - 1670202 - The event_streams table does not get auto-vacuumed

CVEs

  • CVE-2018-11627

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.6/html/release_notes
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat CloudForms 4.6

SRPM
cfme-5.9.8.1-1.el7cf.src.rpm SHA-256: 8ea506346d9da6c748a0b2b6afd403e32eacc3d238727a376e05e14eb1204261
cfme-amazon-smartstate-5.9.8.1-1.el7cf.src.rpm SHA-256: 81dbdbd2ffc6a1b0c756cae7b37ed73ab551e76af83e6c7202f0c84f1e421845
cfme-appliance-5.9.8.1-1.el7cf.src.rpm SHA-256: 13d939cbad2ec0e181419349effc5a736edc0158146311b15df90a3db855a075
cfme-gemset-5.9.8.1-1.el7cf.src.rpm SHA-256: 25c787ed46e4d35df8bcf288ae0da49d1fd156ff3db0fca3df59a047876d6a87
dbus-api-service-1.0.1-3.2.el7cf.src.rpm SHA-256: 7628d27831c6b2f0913e6a0fef9fec81b57a2c5e60ab287a363926d32e4d87f7
x86_64
cfme-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: 9e0dd1f4007b85f58871bf73f7143d8cb7720b6832faac7d07a96369083e0d0f
cfme-amazon-smartstate-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: 8ac49c92b6d0577f290ebacf5271e0dcda1184d523e8c2376e901c67d5240bb5
cfme-appliance-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: 8f35d380f46f6fcf205744504ff41ff8f80b886cbf76aa72179483fce7ee51e0
cfme-appliance-common-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: 21f5030764c2acf6da11f5ddab55ff450f4febd55719d56adc7588c7b091961d
cfme-appliance-debuginfo-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: 8ef667a23f7c0eaa4cb0b36cb838c2fd81eb3ced1415342d23a6136afcb0e918
cfme-appliance-tools-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: 83b3033f48ae9ab82617e08013d8b77a5f9ba3538f94f0074b6c1e8b4581aba5
cfme-debuginfo-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: ac71abd349eb2dce909583a771f69aafeb020f4bf0b08a06ad81920291315d30
cfme-gemset-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: 445e99e894723ec74d0ee7a28a3d4b588f0183a293541bd7a18ee284e36f3792
cfme-gemset-debuginfo-5.9.8.1-1.el7cf.x86_64.rpm SHA-256: 6b117f965f2f6919f29a3c127d4cd1a711b23858dcb856cdc325dea4229e2f9c
dbus-api-service-1.0.1-3.2.el7cf.x86_64.rpm SHA-256: c0109c584ae7a84579884fd6d6cc63c74bb92a797cffbd54b855ef918d59ae4e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter