Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2019:4201 - Security Advisory
Issued:
2019-12-12
Updated:
2019-12-12

RHSA-2019:4201 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: CloudForms 5.0.1 security, bug fix and enhancement update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for CloudForms Management Engine 5.11.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • cfme: rubygem-rubyzip denial of service via crafted ZIP file (CVE-2019-16892)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

If the postgresql service is running, it will be automatically restarted after installing this update. After installing the updated packages, the httpd daemon will be restarted automatically.

Affected Products

  • Red Hat CloudForms 5.11 x86_64

Fixes

  • BZ - 1713400 - [RFE] Cloud Key pair don't have relationships with owner and group that build this key
  • BZ - 1730066 - Unable to view AWS keypair list as tenant_administrator
  • BZ - 1747179 - [Regression] [ActionView::Template::Error] undefined method `tenant_group?' while setting ownership for key pairs
  • BZ - 1767548 - Remove .py extension from calls to virt-v2v-wrapper
  • BZ - 1767549 - Run the preflight check of migration task before waiting for a conversion host
  • BZ - 1767550 - [RFE] Add ability to remove all snapshots asynchronously
  • BZ - 1767645 - [RFE] Hide the Configuration -> Database screen
  • BZ - 1767646 - Unassigned buttons of a Service shows when its Catalog Item has custom buttons
  • BZ - 1767647 - Unable to access "Automate/Requests" tab for a role without exposing "Service/Requests"
  • BZ - 1767648 - Server Error (API) when creating Orchestration Template with duplicate content
  • BZ - 1767656 - [Regression] Unable to capture memory metric from Azure instances
  • BZ - 1767659 - Chargeback report preview fails
  • BZ - 1767660 - Service Requests Requester dropdown not sorted
  • BZ - 1767774 - appliance_console_cli returns 0 on failure
  • BZ - 1767775 - [RFE] Add AWS Bahrain region to CFME
  • BZ - 1767776 - [RFE] - Update Host/Node filter to reflect supported versions of ESX
  • BZ - 1767777 - Typo on list of Host/Nodes global filters -- Status / Orphaned
  • BZ - 1767783 - [RFE] Dis-allow the addition of ESX hosts directly
  • BZ - 1767784 - Unable to receive "generalize" event from Azure after generalizing an instance
  • BZ - 1767786 - API should not declare HTTP DELETE verb on pxe_servers collection
  • BZ - 1767788 - The UI warning about RSA is deprecated and not true anymore.
  • BZ - 1767789 - Passwords stored in variables(extra_vars) are visible in clear text in the Appliance evm.log
  • BZ - 1767790 - there are exceptions "rescue in type_cast" in logs in global and remote region appliances
  • BZ - 1767791 - Chargeback reports not working
  • BZ - 1767796 - Add support for VM conversion host in RHV
  • BZ - 1767809 - UI crashes when going to Details of Azure Network Port somehow associated to Load Balancers
  • BZ - 1767810 - Traceback when clicking on Overview > Chargeback > Reports
  • BZ - 1767811 - [RHV] Last Boot Time is "N/A" for VM if you shutdown guest
  • BZ - 1767818 - [Regression] top_output.log only showing ruby and not the process names
  • BZ - 1767819 - unable to remove duplicate guest devices due to memory
  • BZ - 1767821 - [RFE] Remove list view button on my service sui page if there is no use of it
  • BZ - 1767823 - [RFE] Generic Object builder tab cycle missing the add (commit) remove buttons
  • BZ - 1767824 - multiple workers start the same retirement when retirement date is reached
  • BZ - 1767833 - [UI] Erroneous behavior of spinner and spinner box in advanced search loading
  • BZ - 1767834 - Refresh of OpenShift provider in CloudForms happen to panic apiserver
  • BZ - 1767835 - Changing groups with a user assigned to multiple groups logs out of appliance
  • BZ - 1767836 - Choice in Drop Down that References Category (Tag Control Item) is Incorrect
  • BZ - 1767837 - [RFE] Automating the generation of widget content Via RESTAPI
  • BZ - 1767880 - evm.log is full of error messages "cannot obtain exclusive access to locked queue"
  • BZ - 1767881 - Host creds validation fails if host's ssh key has changed before
  • BZ - 1767885 - [RFE] VMware guests are incorrectly marked as linked_clone true, remove attribute
  • BZ - 1767886 - [RFE] custom service catalog icons being deleted are not actually deleted
  • BZ - 1767895 - [NoMethodError]: undefined method `path' for nil:NilClass Method:[block (2 levels) in <class:LogProxy>] during scheduled NFS backup
  • BZ - 1767896 - Lifecycle retirement fails for user that no longer has groups
  • BZ - 1767901 - [RFE] automate method to delete a tag from a category
  • BZ - 1768456 - Date picker takes a date previous to what is selected in the dialog
  • BZ - 1768517 - [RFE] validate infra mappings
  • BZ - 1768520 - [v2v] Ordering a migration plan, that contains MIGRATED VM/s, fails with an unclear error message.
  • BZ - 1768525 - Remove Automate code for TransformationHost
  • BZ - 1768530 - Add conversion host validation for config params
  • BZ - 1768576 - Sporadic 404 Error when deleting custom button on generic object class
  • BZ - 1768638 - [RFE] Import/export schedules to replicate on other sites
  • BZ - 1771298 - CVE-2019-16892 cfme: rubygem-rubyzip denial of service via crafted ZIP file
  • BZ - 1771737 - ping endpoint fails with "Error caught: [ActionView::MissingTemplate] Missing template ping/index"
  • BZ - 1773666 - [RFE] Custom button: generic class level button deletion not showing a specific flash message
  • BZ - 1773667 - Incorrect flash when custom button under generic object class is deleted
  • BZ - 1775684 - Need the ability to configure the appliance for SAML using the appliance console CLI.

CVEs

  • CVE-2019-16892

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_cloudforms/5.0/html/release_notes
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat CloudForms 5.11

SRPM
cfme-5.11.1.2-1.el8cf.src.rpm SHA-256: 920a15197d7279353704944b6c1e172c7d4edba4e7a01e821ccc4d03462836bf
cfme-amazon-smartstate-5.11.1.2-1.el8cf.src.rpm SHA-256: a107ddbcfa62ffd17f2dc3ef82547a142412090d1fd39e93b10320bc3933b845
cfme-appliance-5.11.1.2-1.el8cf.src.rpm SHA-256: b6b0663bd6002039169347a6eec883f088ab82d6f46d47a17de66a346212d35d
cfme-gemset-5.11.1.2-1.el8cf.src.rpm SHA-256: 12280438dce3ebc16dcb2a859ed6d7d0e3f6b7bbfa4e1e69de3c2ffac63689d9
ovirt-ansible-hosted-engine-setup-1.0.28-1.el8ev.src.rpm SHA-256: 3d2d3723230d33be92fcc8687c1cea5ca1ca99d1a62b2f5a53639e1e38f158be
v2v-conversion-host-1.15.0-1.el8ev.src.rpm SHA-256: 87a6a621f62c1c25f9a50d5945a9beba9c40e0651aef3d81374bd7c319811ae4
x86_64
cfme-5.11.1.2-1.el8cf.x86_64.rpm SHA-256: 079672d87d29b4f37b410c75ec9095a773fb9ba9f1b37b745aa5843ebb53425f
cfme-amazon-smartstate-5.11.1.2-1.el8cf.x86_64.rpm SHA-256: af41bee9bc422adbdfeb10859408b1a96d1dbc9086cb69a9a1ca988679c393ec
cfme-appliance-5.11.1.2-1.el8cf.x86_64.rpm SHA-256: 13bf7662de695b1305c12a325df2767595dacd8aecdf0362a27962f2b305023b
cfme-appliance-common-5.11.1.2-1.el8cf.x86_64.rpm SHA-256: bb1fae6a832cdf4cf591444d68a703d1e3f1e21ec5a917e2716b7e42fb5db824
cfme-appliance-tools-5.11.1.2-1.el8cf.x86_64.rpm SHA-256: 3bc1667fc7b896e25fd4a6807030bf37fa1e360e2c3dc4decc11aeb6dd89d31b
cfme-gemset-5.11.1.2-1.el8cf.x86_64.rpm SHA-256: fe8923e50897c94c7765e73ec9df75a279a818983b07d88a76337c3220cf9e14
ovirt-ansible-hosted-engine-setup-1.0.28-1.el8ev.noarch.rpm SHA-256: 996e5b443b7d13a2f797e90d3c1ee902ada0e50c5052881d113a38ca48b51308
v2v-conversion-host-ansible-1.15.0-1.el8ev.noarch.rpm SHA-256: ddcaddef5fdf0e4b55c08f62b35d40ed054cf250505c82a46b26f50fa9fee7d5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility