Site icon API Security Blog

(RHSA-2022:4711) Moderate: RHV Manager (ovirt-engine) [ovirt-4.5.0] security update

The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning.

Security Fix(es):

* nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)

* nodejs-trim-off-newlines: ReDoS via string processing (CVE-2021-23425)

* normalize-url: ReDoS for data URLs (CVE-2021-33502)

* jquery-ui: XSS in the altField option of the datepicker widget (CVE-2021-41182)

* jquery-ui: XSS in *Text options of the datepicker widget (CVE-2021-41183)

* jquery-ui: XSS in the ‘of’ option of the .position() util (CVE-2021-41184)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

A list of bugs fixed in this update is available in the Technical Notes book:

https://access.redhat.com/documentation/en-us/red_hat_virtualization/4.4/html-single/technical_notesRead More

Exit mobile version