RHBA-2020:2396LowCVSS 3.1
Red Hat Bug Fix Advisory: Red Hat Virtualization Engine security, bug fix 4.3.10
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-1720 — postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks
🎯 Affected products39
- RHV-M 4.3
- ovirt-engine-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-0:4.3.10.3-0.2.el7.src as a component of RHV-M 4.3
- ovirt-engine-backend-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-dbscripts-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-extensions-api-impl-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-extensions-api-impl-javadoc-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-health-check-bundler-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-restapi-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-setup-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-setup-base-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-setup-plugin-cinderlib-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-setup-plugin-ovirt-engine-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-setup-plugin-ovirt-engine-common-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-setup-plugin-vmconsole-proxy-helper-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-setup-plugin-websocket-proxy-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-tools-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-tools-backup-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-vmconsole-proxy-helper-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-webadmin-portal-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- ovirt-engine-websocket-proxy-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- python2-ovirt-engine-lib-0:4.3.10.3-0.2.el7.noarch as a component of RHV-M 4.3
- rh-postgresql10-postgresql-0:10.12-2.el7.src as a component of RHV-M 4.3
- rh-postgresql10-postgresql-0:10.12-2.el7.x86_64 as a component of RHV-M 4.3
- rh-postgresql10-postgresql-contrib-0:10.12-2.el7.x86_64 as a component of RHV-M 4.3
- rh-postgresql10-postgresql-contrib-syspaths-0:10.12-2.el7.x86_64 as a component of RHV-M 4.3
- rh-postgresql10-postgresql-debuginfo-0:10.12-2.el7.x86_64 as a component of RHV-M 4.3
- rh-postgresql10-postgresql-devel-0:10.12-2.el7.x86_64 as a component of RHV-M 4.3
- rh-postgresql10-postgresql-docs-0:10.12-2.el7.x86_64 as a component of RHV-M 4.3
- rh-postgresql10-postgresql-libs-0:10.12-2.el7.x86_64 as a component of RHV-M 4.3
- +9 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHBA-2020:2396
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1717336
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1764779
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1796136
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817450
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820642
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1826789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827350
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827611
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828067
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1832218
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhba-2020_2396.json