RHEL 7 : Red Hat CloudForms (RHSA-2018:0374)

high Nessus Plugin ID 194051

Synopsis

The remote Red Hat host is missing a security update.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2018:0374 advisory.

Ansible is a simple model-driven configuration management, multi-node deployment, and remote-task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.

Ansible Tower helps you scale IT automation, manage complex deployments and speed productivity. Centralize and control your IT infrastructure with a visual dashboard, role-based access control, job scheduling, integrated notifications and graphical inventory management. And Ansible Tower's REST API and CLI make it easy to embed Ansible Tower into existing tools and processes.

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

* A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make changes to settings in the VMRC and virtual machines controlled by it that they should not have access to.
(CVE-2017-12191)

This issue was discovered by Gellert Kis (Red Hat).

Additional Changes:

This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=1458929

https://bugzilla.redhat.com/show_bug.cgi?id=1459190

https://bugzilla.redhat.com/show_bug.cgi?id=1460377

https://bugzilla.redhat.com/show_bug.cgi?id=1460815

https://bugzilla.redhat.com/show_bug.cgi?id=1461164

https://bugzilla.redhat.com/show_bug.cgi?id=1463422

https://bugzilla.redhat.com/show_bug.cgi?id=1478518

https://bugzilla.redhat.com/show_bug.cgi?id=1478520

https://bugzilla.redhat.com/show_bug.cgi?id=1479402

https://bugzilla.redhat.com/show_bug.cgi?id=1479939

https://bugzilla.redhat.com/show_bug.cgi?id=1479940

https://bugzilla.redhat.com/show_bug.cgi?id=1481378

https://bugzilla.redhat.com/show_bug.cgi?id=1481446

https://bugzilla.redhat.com/show_bug.cgi?id=1487306

https://bugzilla.redhat.com/show_bug.cgi?id=1489697

https://bugzilla.redhat.com/show_bug.cgi?id=1490416

https://bugzilla.redhat.com/show_bug.cgi?id=1496900

https://bugzilla.redhat.com/show_bug.cgi?id=1496903

https://bugzilla.redhat.com/show_bug.cgi?id=1496904

https://bugzilla.redhat.com/show_bug.cgi?id=1496907

https://bugzilla.redhat.com/show_bug.cgi?id=1496908

https://bugzilla.redhat.com/show_bug.cgi?id=1496909

https://bugzilla.redhat.com/show_bug.cgi?id=1496922

https://bugzilla.redhat.com/show_bug.cgi?id=1496925

https://bugzilla.redhat.com/show_bug.cgi?id=1496930

https://bugzilla.redhat.com/show_bug.cgi?id=1496931

https://bugzilla.redhat.com/show_bug.cgi?id=1496932

https://bugzilla.redhat.com/show_bug.cgi?id=1496936

https://bugzilla.redhat.com/show_bug.cgi?id=1496937

https://bugzilla.redhat.com/show_bug.cgi?id=1496939

https://bugzilla.redhat.com/show_bug.cgi?id=1496943

https://bugzilla.redhat.com/show_bug.cgi?id=1496945

https://bugzilla.redhat.com/show_bug.cgi?id=1496947

https://bugzilla.redhat.com/show_bug.cgi?id=1496949

https://bugzilla.redhat.com/show_bug.cgi?id=1497209

https://bugzilla.redhat.com/show_bug.cgi?id=1498506

https://bugzilla.redhat.com/show_bug.cgi?id=1498511

https://bugzilla.redhat.com/show_bug.cgi?id=1498516

https://bugzilla.redhat.com/show_bug.cgi?id=1498518

https://bugzilla.redhat.com/show_bug.cgi?id=1498525

https://bugzilla.redhat.com/show_bug.cgi?id=1498542

https://bugzilla.redhat.com/show_bug.cgi?id=1498544

https://bugzilla.redhat.com/show_bug.cgi?id=1498891

https://bugzilla.redhat.com/show_bug.cgi?id=1500029

https://bugzilla.redhat.com/show_bug.cgi?id=1500445

https://bugzilla.redhat.com/show_bug.cgi?id=1500448

https://bugzilla.redhat.com/show_bug.cgi?id=1500517

https://bugzilla.redhat.com/show_bug.cgi?id=1500808

https://bugzilla.redhat.com/show_bug.cgi?id=1500954

https://bugzilla.redhat.com/show_bug.cgi?id=1501475

https://bugzilla.redhat.com/show_bug.cgi?id=1501481

https://bugzilla.redhat.com/show_bug.cgi?id=1501524

https://bugzilla.redhat.com/show_bug.cgi?id=1501897

https://bugzilla.redhat.com/show_bug.cgi?id=1503611

https://bugzilla.redhat.com/show_bug.cgi?id=1503639

https://bugzilla.redhat.com/show_bug.cgi?id=1504199

https://bugzilla.redhat.com/show_bug.cgi?id=1504775

https://bugzilla.redhat.com/show_bug.cgi?id=1505415

https://bugzilla.redhat.com/show_bug.cgi?id=1505456

https://bugzilla.redhat.com/show_bug.cgi?id=1505501

https://bugzilla.redhat.com/show_bug.cgi?id=1505503

https://bugzilla.redhat.com/show_bug.cgi?id=1505545

https://bugzilla.redhat.com/show_bug.cgi?id=1505951

https://bugzilla.redhat.com/show_bug.cgi?id=1506624

https://bugzilla.redhat.com/show_bug.cgi?id=1509008

https://bugzilla.redhat.com/show_bug.cgi?id=1509024

https://bugzilla.redhat.com/show_bug.cgi?id=1509378

https://bugzilla.redhat.com/show_bug.cgi?id=1509391

https://bugzilla.redhat.com/show_bug.cgi?id=1509414

https://bugzilla.redhat.com/show_bug.cgi?id=1509419

https://bugzilla.redhat.com/show_bug.cgi?id=1509423

https://bugzilla.redhat.com/show_bug.cgi?id=1510054

https://bugzilla.redhat.com/show_bug.cgi?id=1510142

https://bugzilla.redhat.com/show_bug.cgi?id=1510175

https://bugzilla.redhat.com/show_bug.cgi?id=1510241

https://bugzilla.redhat.com/show_bug.cgi?id=1510564

https://bugzilla.redhat.com/show_bug.cgi?id=1510698

https://bugzilla.redhat.com/show_bug.cgi?id=1511032

https://bugzilla.redhat.com/show_bug.cgi?id=1511125

https://bugzilla.redhat.com/show_bug.cgi?id=1511130

https://bugzilla.redhat.com/show_bug.cgi?id=1511135

https://bugzilla.redhat.com/show_bug.cgi?id=1511142

https://bugzilla.redhat.com/show_bug.cgi?id=1511144

https://bugzilla.redhat.com/show_bug.cgi?id=1511147

https://bugzilla.redhat.com/show_bug.cgi?id=1511196

https://bugzilla.redhat.com/show_bug.cgi?id=1511502

https://bugzilla.redhat.com/show_bug.cgi?id=1511517

https://bugzilla.redhat.com/show_bug.cgi?id=1511528

https://bugzilla.redhat.com/show_bug.cgi?id=1511548

https://bugzilla.redhat.com/show_bug.cgi?id=1511595

https://bugzilla.redhat.com/show_bug.cgi?id=1512661

https://bugzilla.redhat.com/show_bug.cgi?id=1512665

https://bugzilla.redhat.com/show_bug.cgi?id=1512667

https://bugzilla.redhat.com/show_bug.cgi?id=1512694

https://bugzilla.redhat.com/show_bug.cgi?id=1512695

https://bugzilla.redhat.com/show_bug.cgi?id=1512706

https://bugzilla.redhat.com/show_bug.cgi?id=1512728

https://bugzilla.redhat.com/show_bug.cgi?id=1512955

https://bugzilla.redhat.com/show_bug.cgi?id=1512967

https://bugzilla.redhat.com/show_bug.cgi?id=1513124

https://bugzilla.redhat.com/show_bug.cgi?id=1513509

https://bugzilla.redhat.com/show_bug.cgi?id=1513699

https://bugzilla.redhat.com/show_bug.cgi?id=1514139

https://bugzilla.redhat.com/show_bug.cgi?id=1514184

https://bugzilla.redhat.com/show_bug.cgi?id=1514570

https://bugzilla.redhat.com/show_bug.cgi?id=1515367

https://bugzilla.redhat.com/show_bug.cgi?id=1515402

https://bugzilla.redhat.com/show_bug.cgi?id=1515407

https://bugzilla.redhat.com/show_bug.cgi?id=1515416

https://bugzilla.redhat.com/show_bug.cgi?id=1515426

https://bugzilla.redhat.com/show_bug.cgi?id=1515483

https://bugzilla.redhat.com/show_bug.cgi?id=1518357

https://bugzilla.redhat.com/show_bug.cgi?id=1518368

https://bugzilla.redhat.com/show_bug.cgi?id=1518372

https://bugzilla.redhat.com/show_bug.cgi?id=1518374

https://bugzilla.redhat.com/show_bug.cgi?id=1518383

https://bugzilla.redhat.com/show_bug.cgi?id=1518392

https://bugzilla.redhat.com/show_bug.cgi?id=1518600

https://bugzilla.redhat.com/show_bug.cgi?id=1519809

https://bugzilla.redhat.com/show_bug.cgi?id=1519910

https://bugzilla.redhat.com/show_bug.cgi?id=1519915

https://bugzilla.redhat.com/show_bug.cgi?id=1519987

https://bugzilla.redhat.com/show_bug.cgi?id=1520541

https://bugzilla.redhat.com/show_bug.cgi?id=1520557

https://bugzilla.redhat.com/show_bug.cgi?id=1521036

https://bugzilla.redhat.com/show_bug.cgi?id=1522951

https://bugzilla.redhat.com/show_bug.cgi?id=1523402

https://bugzilla.redhat.com/show_bug.cgi?id=1523404

https://bugzilla.redhat.com/show_bug.cgi?id=1523408

https://bugzilla.redhat.com/show_bug.cgi?id=1523771

https://bugzilla.redhat.com/show_bug.cgi?id=1523773

https://bugzilla.redhat.com/show_bug.cgi?id=1523774

https://bugzilla.redhat.com/show_bug.cgi?id=1523777

https://bugzilla.redhat.com/show_bug.cgi?id=1523788

https://bugzilla.redhat.com/show_bug.cgi?id=1523851

https://bugzilla.redhat.com/show_bug.cgi?id=1523855

https://bugzilla.redhat.com/show_bug.cgi?id=1524646

https://bugzilla.redhat.com/show_bug.cgi?id=1525092

https://bugzilla.redhat.com/show_bug.cgi?id=1525551

https://bugzilla.redhat.com/show_bug.cgi?id=1525563

https://bugzilla.redhat.com/show_bug.cgi?id=1525583

https://bugzilla.redhat.com/show_bug.cgi?id=1526040

https://bugzilla.redhat.com/show_bug.cgi?id=1526473

https://bugzilla.redhat.com/show_bug.cgi?id=1527676

https://bugzilla.redhat.com/show_bug.cgi?id=1530653

https://bugzilla.redhat.com/show_bug.cgi?id=1530708

https://bugzilla.redhat.com/show_bug.cgi?id=1530717

https://bugzilla.redhat.com/show_bug.cgi?id=1531146

https://bugzilla.redhat.com/show_bug.cgi?id=1531147

https://bugzilla.redhat.com/show_bug.cgi?id=1531156

https://bugzilla.redhat.com/show_bug.cgi?id=1531161

https://bugzilla.redhat.com/show_bug.cgi?id=1531177

https://bugzilla.redhat.com/show_bug.cgi?id=1531178

https://bugzilla.redhat.com/show_bug.cgi?id=1531256

https://bugzilla.redhat.com/show_bug.cgi?id=1531261

https://bugzilla.redhat.com/show_bug.cgi?id=1531262

https://bugzilla.redhat.com/show_bug.cgi?id=1531274

https://bugzilla.redhat.com/show_bug.cgi?id=1531554

https://bugzilla.redhat.com/show_bug.cgi?id=1531615

https://bugzilla.redhat.com/show_bug.cgi?id=1531618

https://bugzilla.redhat.com/show_bug.cgi?id=1531619

https://bugzilla.redhat.com/show_bug.cgi?id=1532328

https://bugzilla.redhat.com/show_bug.cgi?id=1532854

https://bugzilla.redhat.com/show_bug.cgi?id=1532857

https://bugzilla.redhat.com/show_bug.cgi?id=1533167

https://bugzilla.redhat.com/show_bug.cgi?id=1533169

https://bugzilla.redhat.com/show_bug.cgi?id=1533171

https://bugzilla.redhat.com/show_bug.cgi?id=1534584

https://bugzilla.redhat.com/show_bug.cgi?id=1534589

https://bugzilla.redhat.com/show_bug.cgi?id=1534591

https://bugzilla.redhat.com/show_bug.cgi?id=1534601

https://bugzilla.redhat.com/show_bug.cgi?id=1536052

https://bugzilla.redhat.com/show_bug.cgi?id=1536672

https://bugzilla.redhat.com/show_bug.cgi?id=1537015

https://bugzilla.redhat.com/show_bug.cgi?id=1537145

https://bugzilla.redhat.com/show_bug.cgi?id=1537284

https://bugzilla.redhat.com/show_bug.cgi?id=1538349

https://bugzilla.redhat.com/show_bug.cgi?id=1538350

https://bugzilla.redhat.com/show_bug.cgi?id=1538351

https://bugzilla.redhat.com/show_bug.cgi?id=1539752

https://bugzilla.redhat.com/show_bug.cgi?id=1540699

https://bugzilla.redhat.com/show_bug.cgi?id=1541072

https://bugzilla.redhat.com/show_bug.cgi?id=1542170

https://bugzilla.redhat.com/show_bug.cgi?id=1542240

https://bugzilla.redhat.com/show_bug.cgi?id=1542577

https://bugzilla.redhat.com/show_bug.cgi?id=1542741

https://bugzilla.redhat.com/show_bug.cgi?id=1543121

https://bugzilla.redhat.com/show_bug.cgi?id=1543150

https://bugzilla.redhat.com/show_bug.cgi?id=1543172

http://www.nessus.org/u?c0261402

https://access.redhat.com/errata/RHSA-2018:0374

Plugin Details

Severity: High

ID: 194051

File Name: redhat-RHSA-2018-0374.nasl

Version: 1.1

Type: local

Agent: unix

Published: 4/27/2024

Updated: 6/3/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.0

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2017-12191

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:ansible-tower-server, p-cpe:/a:redhat:enterprise_linux:python-paramiko-doc, p-cpe:/a:redhat:enterprise_linux:python2-jmespath, p-cpe:/a:redhat:enterprise_linux:python-crypto, p-cpe:/a:redhat:enterprise_linux:cfme-gemset, p-cpe:/a:redhat:enterprise_linux:postgresql94, p-cpe:/a:redhat:enterprise_linux:ansible-tower-setup, p-cpe:/a:redhat:enterprise_linux:postgresql94-docs, p-cpe:/a:redhat:enterprise_linux:postgresql94-plperl, p-cpe:/a:redhat:enterprise_linux:postgresql94-server, p-cpe:/a:redhat:enterprise_linux:cfme, p-cpe:/a:redhat:enterprise_linux:postgresql94-contrib, p-cpe:/a:redhat:enterprise_linux:postgresql94-plpython, p-cpe:/a:redhat:enterprise_linux:cfme-appliance, p-cpe:/a:redhat:enterprise_linux:python-jmespath, p-cpe:/a:redhat:enterprise_linux:postgresql94-test, p-cpe:/a:redhat:enterprise_linux:postgresql94-pltcl, p-cpe:/a:redhat:enterprise_linux:postgresql94-devel, p-cpe:/a:redhat:enterprise_linux:ansible, p-cpe:/a:redhat:enterprise_linux:python2-crypto, cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:postgresql94-libs, p-cpe:/a:redhat:enterprise_linux:python-paramiko

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 2/28/2018

Vulnerability Publication Date: 2/28/2018

Reference Information

CVE: CVE-2017-12191

CWE: 284

RHSA: 2018:0374