RHSA-2020:1308: Low: Red Hat Virtualization Engine security, bug fix 4.3.9
The org.ovirt.engine-root is a core component of oVirt.The following packages have been upgraded to a later upstream version: org.ovirt.engine-root (4.3.8.2), ovirt-engine-dwh (4.3.8), ovirt-engine-metrics (1.3.6.1), ovirt-fast-forward-upgrade (1.0.0), ovirt-imageio-common (1.5.3), ovirt-imageio-proxy (1.5.3), ovirt-web-ui (1.6.0), rhv-log-collector-analyzer (0.2.15), v2v-conversion-host (1.16.0). (BZ#1767333, BZ#1776722, BZ#1779587, BZ#1779631)Security Fix(es): CVE-2019-17195 CVE-2019-10086 For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [downstream clone - 4.4.0] Upgrade from 4.3 to 4.4 will fail if there are versioned templates in database (BZ#1688781) [ovirt-fast-forward-upgrade] Error: ovirt-engine-setup-plugin-ovirt-engine conflicts with ovirt-engine-4.2.5.2-0.1.el7ev.noarch (BZ#1754979) Users immediately logged out from User portal due to negative UserSessionTimeOutInterval (BZ#1757423) Fluentd error when stopping metrics services through playbook on 4.3 (BZ#1772506) [downstream clone - 4.3.8] From VM Portal, users cannot create Operating System Windows VM. (BZ#1773580) MERGESTATUS fails with 'Invalid UUID string: mapper' when Direct LUN that already exists is hot-plugged [RHV clone - 4.3.8] (BZ#1779664) Metric Store reports all hosts in Default cluster regardless of cluster assignment. (BZ#1780234) Enhancement(s): RFE for offline installation of RHV Metrics Store (BZ#1711873) [RFE] Compare storage with database for discrepancies (BZ#1739106) [RFE] RHV+Metrics Store - Support a Flat DNS environment without subdomains (BZ#1782412)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1308?
The severity of RHSA-2020:1308 is categorized as a moderate vulnerability.
How do I fix RHSA-2020:1308?
To fix RHSA-2020:1308, upgrade the affected packages to the versions specified in the advisory.
Which packages are affected by RHSA-2020:1308?
RHSA-2020:1308 affects several packages including ovirt-engine, ovirt-engine-dwh, and others.
What is the purpose of ovirt-engine featured in RHSA-2020:1308?
The ovirt-engine is a core component for managing virtualization in oVirt.
Is there a recommended version to upgrade for RHSA-2020:1308?
Yes, it is recommended to upgrade to version 4.3.9.3-0.1.el7 for the affected packages.