Red Hat Security Advisory: RHV Manager (ovirt-engine) [ovirt-4.5.1] security, bug fix and update
🔗 CVE IDs covered (9)
📋 Description
CVE-2021-3807 — nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes CVE-2021-22096 — springframework: malicious input leads to insertion of additional log entries CVE-2021-33623 — nodejs-trim-newlines: ReDoS in .end() method CVE-2021-35515 — apache-commons-compress: infinite loop when reading a specially crafted 7Z archive CVE-2021-35516 — apache-commons-compress: excessive memory allocation when reading a specially crafted 7Z archive CVE-2021-35517 — apache-commons-compress: excessive memory allocation when reading a specially crafted TAR archive CVE-2021-36090 — apache-commons-compress: excessive memory allocation when reading a specially crafted ZIP archive CVE-2022-22950 — spring-expression: Denial of service via specially crafted SpEL expression CVE-2022-31051 — semantic-release: Masked secrets can be disclosed if they contain characters that are excluded from uri encoding
🎯 Affected products44
- RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- apache-commons-compress-0:1.21-1.2.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- apache-commons-compress-0:1.21-1.2.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- apache-commons-compress-javadoc-0:1.21-1.2.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-dependencies-0:4.5.2-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-dependencies-0:4.5.2-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-0:4.5.1.2-0.11.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-backend-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dbscripts-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-0:4.5.3-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-0:4.5.3-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-grafana-integration-setup-0:4.5.3-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-dwh-setup-0:4.5.3-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-health-check-bundler-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-restapi-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-base-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-cinderlib-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-imageio-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-ovirt-engine-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-ovirt-engine-common-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-vmconsole-proxy-helper-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-setup-plugin-websocket-proxy-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-tools-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-tools-backup-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-ui-extensions-0:1.3.4-1.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-ui-extensions-0:1.3.4-1.el8ev.src as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-vmconsole-proxy-helper-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- ovirt-engine-webadmin-portal-0:4.5.1.2-0.11.el8ev.noarch as a component of RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4
- +14 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 Workaround: Users should ensure that secrets that do not contain characters that are excluded from encoding with `encodeURI` when included in a URL that is already masked properly.
🔗 References (33)
- selfhttps://access.redhat.com/errata/RHSA-2022:5555
- externalhttps://access.redhat.com/documentation/en-us/red_hat_virtualization/4.4/html-single/technical_notes
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1663217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1782077
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1849045
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1852308
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1958032
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966615
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1976607
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981895
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981900
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981903
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981909
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1994144
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2001574
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2001923
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2006625
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2007557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030293
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2068270
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069414
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2070045
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072626
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081241
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081559
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092885
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2093795
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2097414
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2099650
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5555.json