RHSA-2020:3807MediumCVSS 7.4
Red Hat Security Advisory: Red Hat Virtualization security, bug fix, and enhancement update
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-8203 — nodejs-lodash: prototype pollution in zipObjectDeep function CVE-2020-11022 — jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods CVE-2020-14333 — ovirt-engine: Reflected cross site scripting vulnerability
🎯 Affected products43
- RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ansible-runner-service-0:1.0.5-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ansible-runner-service-0:1.0.5-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-0:4.4.2.3-0.6.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-backend-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dbscripts-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-0:4.4.2.1-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-0:4.4.2.1-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-grafana-integration-setup-0:4.4.2.1-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-setup-0:4.4.2.1-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-extension-aaa-ldap-0:1.4.1-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-extension-aaa-ldap-0:1.4.1-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-extension-aaa-ldap-setup-0:1.4.1-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-health-check-bundler-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-restapi-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-base-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-cinderlib-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-imageio-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-ovirt-engine-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-ovirt-engine-common-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-vmconsole-proxy-helper-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-websocket-proxy-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-tools-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-tools-backup-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-ui-extensions-0:1.2.3-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-ui-extensions-0:1.2.3-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-vmconsole-proxy-helper-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-webadmin-portal-0:4.4.2.3-0.6.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- +13 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (43)
- selfhttps://access.redhat.com/errata/RHSA-2020:3807
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1625499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1638217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1643520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1674420
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1748879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1749803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1758024
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1763812
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1778471
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1787854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1801206
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1803856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1804037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1804046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816951
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1819260
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1826255
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1831949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1831952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1831954
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1831956
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1838051
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1841112
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1843234
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1850004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1854488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1855377
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1858184
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1859460
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1860907
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1866466
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1866734
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1869209
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1869302
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1871235
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1875609
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1875851
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3807.json