RHSA-2022:4711: Moderate: RHV Manager (ovirt-engine) [ovirt-4.5.0] security update
The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning.<br>Security Fix(es):<br><li> nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)</li> <li> nodejs-trim-off-newlines: ReDoS via string processing (CVE-2021-23425)</li> <li> normalize-url: ReDoS for data URLs (CVE-2021-33502)</li> <li> jquery-ui: XSS in the altField option of the datepicker widget (CVE-2021-41182)</li> <li> jquery-ui: XSS in Text options of the datepicker widget (CVE-2021-41183)</li> <li> jquery-ui: XSS in the 'of' option of the .position() util (CVE-2021-41184)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>A list of bugs fixed in this update is available in the Technical Notes book:<br><a href="https://access.redhat.com/documentation/en-us/redhatvirtualization/4.4/html-single/technicalnotes" target="blank">https://access.redhat.com/documentation/en-us/redhatvirtualization/4.4/html-single/technicalnotes</a>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:4711?
The RHSA-2022:4711 vulnerability is categorized as a moderate severity issue.
How do I fix RHSA-2022:4711?
To resolve RHSA-2022:4711, update to the recommended package versions specified in the advisory.
What packages are affected by RHSA-2022:4711?
RHSA-2022:4711 affects various packages including ovirt-engine, ansible-runner, and apache-sshd on the el8 platform.
What is the purpose of the ovirt-engine package mentioned in RHSA-2022:4711?
The ovirt-engine package serves as the Red Hat Virtualization Manager for managing virtual machines and associated resources.
Is there a risk of exploitation associated with RHSA-2022:4711?
Yes, there is a risk of exploitation if the vulnerable packages are not updated in a timely manner.