RHSA-2014:0816High
Red Hat Security Advisory: cfme security, bug fix, and enhancement update
🔗 CVE IDs covered (7)
📋 Description
CVE-2014-0130 — rubygem-actionpack: directory traversal issue CVE-2014-0176 — CFME: reflected XSS in several places due to missing JavaScript escaping CVE-2014-0180 — CFME: app/controllers/application_controller.rb wait_for_task DoS CVE-2014-0184 — CFME: root password is written to evm.log when entered during VM provisioning CVE-2014-0197 — CFME: CSRF protection vulnerability in referrer header CVE-2014-3486 — CFME: SSH Utility insecure tmp file creation leading to code execution as root CVE-2014-3489 — CFME: Default salt value in miq-password.rb
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2014:0816
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1086463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1087909
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1089131
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1095105
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1107528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1107853
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_0816.json