Lucene search

K
redhatRedHatRHSA-2019:2587
HistorySep 05, 2019 - 5:18 a.m.

(RHSA-2019:2587) Moderate: CloudForms 4.7.9 security, bug fix and enhancement update

2019-09-0505:18:52
access.redhat.com
93

0.035 Low

EPSS

Percentile

91.6%

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • cloudforms: stored cross-site scripting in Name field (CVE-2018-10854)

  • js-jquery: prototype pollution in object’s prototype leading to denial of service or remote code execution or property injection (CVE-2019-11358)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.