RHSA-2022:4711MediumCVSS 7.5
Red Hat Security Advisory: RHV Manager (ovirt-engine) [ovirt-4.5.0] security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2021-3807 — nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes CVE-2021-23425 — nodejs-trim-off-newlines: ReDoS via string processing CVE-2021-33502 — nodejs-normalize-url: ReDoS for data URLs CVE-2021-41182 — jquery-ui: XSS in the altField option of the datepicker widget CVE-2021-41183 — jquery-ui: XSS in *Text options of the datepicker widget CVE-2021-41184 — jquery-ui: XSS in the 'of' option of the .position() util
🎯 Affected products54
- RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ansible-runner-0:2.1.3-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ansible-runner-0:2.1.3-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- apache-sshd-1:2.8.0-0.1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- apache-sshd-1:2.8.0-0.1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- apache-sshd-javadoc-1:2.8.0-0.1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- engine-db-query-0:1.6.4-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- engine-db-query-0:1.6.4-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-dependencies-0:4.5.1-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-dependencies-0:4.5.1-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-0:4.5.0.7-0.9.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-backend-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dbscripts-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-0:4.5.2-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-0:4.5.2-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-grafana-integration-setup-0:4.5.2-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-setup-0:4.5.2-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-health-check-bundler-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-metrics-0:1.6.0-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-metrics-0:1.6.0-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-restapi-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-base-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-cinderlib-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-imageio-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-ovirt-engine-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-ovirt-engine-common-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-vmconsole-proxy-helper-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-websocket-proxy-0:4.5.0.7-0.9.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- +24 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891
🔗 References (100)
- selfhttps://access.redhat.com/errata/RHSA-2022:4711
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_virtualization/4.4/html-single/technical_notes
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=655153
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=977778
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1624015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1648985
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1667517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1687845
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1781241
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1782056
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1849169
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1878930
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1922977
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1926625
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1927985
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944290
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944834
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1956295
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1959186
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1964208
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1964461
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971622
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1974741
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1979441
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1979797
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1980192
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986834
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1987121
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1988496
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1990462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991240
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1996123
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1998255
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999698
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2000031
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2002283
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2003883
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2003996
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2006602
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2006745
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2007384
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2007557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2008798
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2010203
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2010903
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2013928
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2014888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2015796
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2019144
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2019148
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2019153
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2021217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2023250
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2023786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024202
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2025936
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030596
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030663
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031027
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2035051
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2037115
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2037121
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040361
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040402
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040474
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041544
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043146
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048546
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050566
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050614
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2051857
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052690
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2054756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2055136
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056126
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2058264
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2059521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2059877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061904
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2065052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066084
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066283
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2070156
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2071468
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072637
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072639
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072641
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072642
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075352
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_4711.json