RHSA-2022:5555: Moderate: RHV Manager (ovirt-engine) [ovirt-4.5.1] security, bug fix and update
The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning.Security Fix(es): nodejs-trim-newlines: ReDoS in .end() method (CVE-2021-33623) apache-commons-compress: infinite loop when reading a specially crafted 7Z archive (CVE-2021-35515) apache-commons-compress: excessive memory allocation when reading a specially crafted 7Z archive (CVE-2021-35516) apache-commons-compress: excessive memory allocation when reading a specially crafted TAR archive (CVE-2021-35517) apache-commons-compress: excessive memory allocation when reading a specially crafted ZIP archive (CVE-2021-36090) nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807) spring-expression: Denial of service via specially crafted SpEL expression (CVE-2022-22950) semantic-release: Masked secrets can be disclosed if they contain characters that are excluded from uri encoding (CVE-2022-31051) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.A list of bugs fixed in this update is available in the Technical Notes book:https://access.redhat.com/documentation/en-us/redhatvirtualization/4.4/html-single/technicalnotes
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5555?
The severity of RHSA-2022:5555 is considered moderate.
How do I fix RHSA-2022:5555?
To fix RHSA-2022:5555, update the affected packages to the recommended versions provided in the advisory.
Which packages are affected by RHSA-2022:5555?
RHSA-2022:5555 affects several packages including ovirt-engine, ovirt-dependencies, and apache-commons-compress.
Is RHSA-2022:5555 a critical vulnerability?
No, RHSA-2022:5555 is classified with a moderate severity rather than critical.
What is the primary product impacted by RHSA-2022:5555?
The primary product impacted by RHSA-2022:5555 is the ovirt-engine package, which is part of the Red Hat Virtualization Manager.