Lucene search

K
redhatRedHatRHSA-2020:2480
HistoryJun 10, 2020 - 1:30 p.m.

(RHSA-2020:2480) Moderate: CloudForms 5.0.6 security, bug fix and enhancement update

2020-06-1013:30:30
access.redhat.com
38

0.002 Low

EPSS

Percentile

65.0%

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • cfme-gemset: rubygem-rack: hijack sessions by using timing attacks targeting the session id (CVE-2019-16782)

  • cfme-amazon-smartstate: rubygem-rack: hijack sessions by using timing attacks targeting the session id (CVE-2019-16782)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.