-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: CFME 5.5.0 bug fixes and enhancement update Advisory ID: RHSA-2015:2551-01 Product: Red Hat CloudForms Advisory URL: https://access.redhat.com/errata/RHSA-2015:2551 Issue date: 2015-12-08 CVE Names: CVE-2015-7502 ===================================================================== 1. Summary: Updated cfme packages that fix a security issue, several bugs, and add various enhancements are now available for Red Hat CloudForms 4.0. Red Hat Product Security has rated this update as having Moderate Security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: CloudForms Management Engine 5.5 - noarch, x86_64 3. Description: Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components. A privilege escalation flaw was discovered in CloudForms, where in certain situations, CloudForms could read encrypted data from the database and then write decrypted data back into the database. If the database was then exported or log files generated, a local attacker might be able to gain access to sensitive information. (CVE-2015-7502) This update also fixes several bugs. Documentation for these changes is available in the Release Notes linked to in the References section. All CFME users are advised to upgrade to these updated packages, which correct these issues and add these enhancements. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1174458 - Trusted Forest bind_pwd is logged in clear text 1174858 - suspended vms on rhevm show 'unknown' 1176631 - Error:" undefined method `description' for nil:NilClass [chargeback/x_button] " in chargeback storage rates 1178213 - Pressing Cancel button on Service Dialog Edit screen displays incorrect flash Message 1181413 - Wrong flash message displayed on save retirement date for a service 1182360 - Disable next and last pagination buttons when all the report data is on a single page 1183092 - [RFE] Control-alt-delete.override update did not overwrite, delete, or change files 1187777 - RBAC: Group context switching affecting provisioning best-fit placement, quota and group ownership 1189157 - RHOS Unable to provision an openstack instance in a non-admin tenant with only a shared network 1193652 - Report based on EVM Groups is not displaying correct tags 1194668 - Buttons on "Add New Host" page disappears after changing form back default values 1195401 - Breadcrumb navigation error while navigating users 1197083 - Validate button in credentials displayed twice 1197841 - [RFE] SmartState Analysis should collect installed date for RPMs 1200137 - SCVMM VM power function failing with error 1202571 - Incorrect flash message after schedule edit is cancelled 1202781 - Change in Server name does not reflect in settings accordion 1202895 - Error with Smart State Analysis on RHEV VM on NFS 1204496 - C&U Performance data ends by 0 1205402 - Paginator has infinite pages 1205498 - Incorrect info bar label on chargeback rates page 1206029 - User role selection is not honored if I uncheck "Everything" in WebUI. 1208373 - 503 error in CFME when connecting RHELOSP with no Swift service 1209740 - Hand pointer on "Number of disks" detail page of a VM. 1210657 - SCVMM - VM CPU Count shows 0 in UI 1211665 - Clicking fleeced "Init processes" on an image summary screen triggers an error. 1211730 - [RFE] Add cloud-init package to the appliance 1212155 - Remove Add,cancel button from control action search result page 1212204 - Automate - Add Services Quota StateMachine to RedHat domain 1212274 - UI : Status of inactive schedule not displayed 1212470 - DateTime control returns the wrong date/time if the chosen date/time is in less that 1h 1212685 - Unhandled Exception Database settings page 1214405 - Foreman UI - configuration manager and configured system search is shared 1215599 - Tool tip of Redo button should be replaced from "Redo the next change" to "Redo the previous change" in the Scope/Condition editor of Control Policy 1215990 - [RFE] Allow the on_entry and on_error methods of a state machine to be able to advance (bump) state to allow processing to continue 1216889 - VM not getting auto power on after provisioning from CFME 3.1 if memory size is more than 4GB 1217002 - "Error during 'Policy Import': undefined method `collect' for "test 'as da ad":String" in control Import/Export 1217097 - VM Retirement Backward Compatibility Information 1217222 - Warn VolMgrPlatformSupportLinux: $miqHostCfg not set 1217226 - SmartState analysis produces xml-related errors in evm.log 1217426 - RBAC: Missing foreman provider tab for operator,desktop,user_self_service and vm_user role 1217545 - Hostname field on new cloud provider page does not trim trailing whitespace 1217641 - database restore fails but doesn't log the error 1217916 - Refresh Power States Fails for OpenStack - No Cinder 1218604 - Foreman provisioning request lands the user on a page with list of requests but no submenu 1219005 - Openstack prov. request - undefined method `fetch_path' for nil:NilClass [miq_request/prov_field_changed] 1219730 - Auto Approve - Max CPU * company tag lists wrong values 1219950 - Dynamic drop down list does not accept first entry 1219998 - Timeout issues with fleecing on OpenStack 1221060 - Satellite 5 organization not displayed in the UI when set 1221386 - dialog values do not override vm_name 1221532 - SCVMM: "[RuntimeError]: Host not specified, unable to migrate VM Method:[rescue in execute]" on VM migrate 1221572 - tag displayed when hovered on a datastore in C & U collection setting page 1221754 - Link to orchestration template is missing from orchestration stack summary page 1221760 - [RFE] Configuring CF to be able to search full tree in ldap 1221821 - UI: OPS/Diagnostics Server, Collect Logs edit form does not populate saved log depot settings 1222155 - RHEL OSP provider passes credentials but fails to refresh environment info 1222182 - no implicit conversion of Symbol into Integer [storage/perf_chart_chooser] while grouping datastore C&U charts by tag 1222183 - RoutingError (No route matches [GET] "/images/icons/new/vendor-foreman_provisioning.png" in production.log 1222479 - RBAC: Configuration accordion misrendered for users having access to configuration feature 1222497 - Openstack cloud provider refresh fails if there are no glance images loaded 1222591 - SSH access to appliance hosted on RHEV-m 3.4 fails with default root credentials 1222642 - RHOS: VM Fleecing throws " ERROR -- : Q-task_id([4bef2b1a-fd6e-11e4-9b8c-0050569674e2]) excon.error # Actual(404 Not Found)" 1222667 - Login page Title does not display appropriately 1222674 - RedHat Domain - Service Quota error for heat stacks. 1222920 - Display flash message if "Add a schedule" in cancelled by the user when creating first schedule 1223016 - [RFE] Provide VHD Image for Microsoft SCVMM support 1223114 - Running Database garbage collection from the UI gives error 1223348 - Unhandled Exception when switching provisioning types 1223368 - Simulation doesn't clear object when reselecting none 1223459 - UI: Configure/My Settings/Default Views is missing a "Configuration Management" item in the Infrastructure section 1223536 - CF ems refresh doesn't find all instances in OSP !>1000 1223567 - Font mixed up on Right size recommendation page for VMs 1223911 - Service : clicking on request with orphaned template shows error 1223976 - Not capturing events properly from RHOS (RabbitMQ) 1224207 - UI: Configure/My Settings/Default Views is missing a "Tenants" item in the clouds section 1224228 - Using OpenStack non-admin user to add an OpenStack provider, doesn't show OpenStack networks 1224425 - Flash message displayed twice after resetting changes while editing compute,storage rates 1224914 - Redhat Satellite Providers configured system shows count as n,but displays n-1. 1224947 - undefined method `paged_view_search' for nil:NilClass [provider_foreman/download_data] in RedHat satellite provider download links 1224959 - Replace term "Foreman" with "Red Hat Satellite" in Provider refresh flash message 1225026 - Scrollbar dips below visible area 1225121 - Vmware VM retirement - undefined method `call_ws' for # 1225145 - Show container default filters only if they are turned on 1225332 - Connection to OSP SSL doesn't get attempted following Errno::ECONNRESET error on non-SSL connection 1225380 - [ja_JP] Unlocalized strings in the Login page. 1225395 - [ja_JP] Unlocalized primary navigation bar name. 1225401 - [ja_JP] Unlocalized sub-tabs name of Configure -> My Settings. 1225408 - [ja_JP] "ja" should be "Japanese" and localized in Locale drop-down list of Configure->My Settings->Visual->Display Settings. 1225432 - [ja_JP] Unlocalized Logout menu. 1226085 - Pipe character on host edit page 1226366 - MIQ(MiqWidget.get_group) Unable to find group '' in evm.log 1226491 - scroll bar on the Default filters page has extra arrow heads 1227045 - [RFE] Filtering of Service Catalog items during deployment 1227068 - Dialog name is not saved for Catalog Bundle for Services 1227069 - [ja_JP] Unexpected and unlocalized string "translation missing: ja.product.name: xx" in the browser window & tab's name and tooltips. 1227211 - Foreman - unable to add a tag during provisioning 1227426 - widget generation issues with groups that have no userid set 1227645 - SMTP authentication configuration changes from login to plain issues 1227659 - Widgets import doesn't work fine 1227703 - Missing reset button in the dashboard, to reset it to default 1227750 - Inconsistent Hover text for compare and drift mode in default view settings 1227811 - Service request cannot be deleted with nonadmin user, even if the permissions are ok 1227931 - Service Quota service_request_rejected automate method puts truncated data in the miq_request reason attribute. 1227937 - Automate - Fix service dialog_parser issue. 1227945 - Automate - Fix RedHat ServiceQuota issue 1228104 - HTML5 console not working with IE8 and IE9 1228130 - Inconsistent title names for exist mode in default view settings and compare page 1228367 - Archived VM instance still connects to its orchestration stack 1228743 - Need to update the japanese locale file 1228844 - Control Explorer: Error when clicking on Policy in Policies accordion 1229104 - undefined method `description' for # [ems_cloud/show] while clicking on openstack provider 1229126 - User logs out when clicked on REDHAT CLOUDFORMS MANAGEMENT title header 1229136 - Disable export button when no custom reports are available for export 1229308 - comparison of Array with Array failed [ops/db_list] while sorting VMDB client connections on Waiting resource 1229326 - Broken styles with UI plugin for external links in CFME menu 1229348 - 5.4 beta - The dialog to add a new Button no longer allows the input of Attribute/Value pairs 1229380 - Orchestration stack provisioning timeout should be in minutes 1229420 - CFME 5.4 beta - Cannot add a Control Action that specifies an Action Type of "Invoke a Custom Automation" 1229431 - Services -> Request shows an exception - undefined method `name' for #Utilization pages with time profiles that have C&U data roll up enabled 1231321 - Availability Zone & Security Group Tags not honoured by Group Tag Filter 1231889 - undefined method `[]' for nil:NilClass [miq_policy/alert_field_changed] 1232281 - Error:"You cannot call create unless the parent is saved [host/create]" in add new host 1232283 - undefined method `strip' for nil:NilClass [host/create] while adding new host 1232484 - OpenStack Event Catcher Thread Constantly Failing and Restarting 1232546 - NoMethodError: undefined method `log' for main:Object 1232548 - [wrong number of arguments (3 for 2)] 1232549 - [undefined method `+' for nil:NilClass] lines 24 + 29 1232924 - Both Request Tasks" and "Tasks" have same description 1233188 - "NotImplementedError (verify_credentials_with_ws not implemented in Host)" when validating credentials for newly added host. 1233815 - Extract running process doesn't work without error message 1233944 - Automate Services Provisioning Issue - Conflict between statemachine completion and task rollup completion. 1234465 - Automate exports use Windows line endings 1234497 - Can not assign a host to a hostgroup without locations 1234588 - undefined method error when looking at bottlenecks under optimize using IE browser 1234871 - SCVMM provider refresh fails where VM disks are not present 1234894 - SCVMM provisioning from template fails for templates with spaces in their name 1234904 - SCVMM provisioning from template fails on SCVMM SP1 1234987 - Custom Buttons are not displayed 1234990 - SCVMM provisioning from template fails to extrapolate the destination storage correctly 1235259 - Dynamic drop downs are executing up to 3 times when a service dialog executes 1235384 - [RFE] SCVMM post provisioning ems refresh takes too long 1235541 - OpenStack tenant visibility not limited by tag 1235822 - Cannot run VM because it is in Powering Up status, encountered during phase autostart_destination 1236174 - [RFE] Automate: Run state machine from within another state machine 1236522 - Refresh button makes interface hang 1236599 - For SCVMM hypervisor, verifying host credentials throws EPIPE 1236977 - Configuration button remains disabled when "check all" is selected 1237091 - VMs / Instances search box is not available (visible) when custom logo is in use 1237110 - Cannot change server's zone from 'default' 1238179 - VM Utilization screen generating charts throws internal server error after Rails 4 1238236 - unknown attribute: resource_action Method:[rescue in block in seed] in 5.3.5.2 1238268 - [RFE] Retrieve Reporting reports from RESTapi 1238271 - [RFE] Retrieve ChargeBack reports from RESTapi 1238287 - [RFE] Monthly Billing - Report to provide watermark sockets of hypervisors 1238288 - [RFE] Monthly Billing - Report to provide watermark vms per provider. 1238390 - cloud-init parameters not being passed to rhev 1238391 - Lifecycle/customize root password logged in clear text. 1238423 - migration error "Process ID out of range error" after evmserverd start 1238443 - Migration: Db:migrate failure when going version 5.2.4 -> 5.4 while uninstalling rubyrep 1238485 - undefined method error raised when viewing hosts 1238530 - Unable to add Infrastructure and cloud providers 1238548 - Adding a new class leads to Blank screen 1238555 - Error when clicking on Optimize tab 1238601 - Flash message doesn't go away upon clicking 1238819 - Update UI labels to include words State Machine for service entry points 1239035 - Update using UI fails to auto-start the server back up 1240309 - Javascript error on refresh of dynamic drop down with nil key 1240337 - Smart state analysis fails on EC2 instances with undefined method ` + 'for nil:NilClass " 1240485 - UI: Titles/Breadcrumbs on Provider screens are incorrect 1240742 - Performance issues in provisioning after initial template selection 1241890 - undefined method `description' for nil:NilClass] encountered during phase [create_pxe_configuration_file] when no pxe image is selected while provisioning 1241972 - Clicking on Host/Services returns exception: undefined method `num_cpu' for nil:NilClass 1242152 - upstream : Error on adding infrastructure provider 1242369 - Spinner spins forever while sorting policy actions 1242459 - accessing to vm_infra/explorer raises "Error caught: [ArgumentError] comparison of Array with Array failed" 1243695 - "Time Zone" (under Chargeback Interval section) in chargeback report is not functioning 1243938 - [Scale] - Inventory of 10k vm provider, 90minutes spent between Updating Folders To Vms relationships to Updating Clusters To Resource Pools relationships 1243983 - Full screen report view error's out with IE 1244370 - Upstream build : Unable to add credentials for Vmware provider 1244943 - UI: when trying to access URL directly pointing to an object after login user remains on dashboard show screen. 1245300 - Refresh button makes interface hang on viewing Request 1245450 - undefined method `name' for "CentOS Server":String [provider_foreman/show] on pdf download in foreman configuration profile page 1245511 - [RHOS] When the admin user is a member but not an admin of a flavour, it raises an error during provider refresh. 1245724 - automate drb load limit error "too large packet" 1246140 - Foreman UI - provider filtering is also being applied to configuration profiles within providers 1246536 - Infrastructure Provider summary. IP Address row header should say "Discovered IP Address" 1246538 - [ActionController::RoutingError] No route matches {:controller=>"vm_or_template", :action=>"launch_html5_console", :id=>1000000000151} 1246546 - "Host Name" should change to "Hostname" in Provider and Host editing forms 1246558 - Resource Pools Properties dropdown expanded by default 1246655 - no way to specify embedded proxy affinity for multi-datastore environments 1246693 - Service dialog : Adding a service dialog of "Drop down list " type without adding entries shows error 1246994 - VM provision dialog shows incorrect cpu count for RHEV CFME templates 1247375 - RBAC: Unable to restrict self-service users from seeing Clouds and / Infrastructure / Requests 1247664 - vm.create_snapshot fails for vmware vm Handsoap::Fault 1248039 - Unable to Importing into a new Automate Domain if a custom domain exist 1248181 - Cloud Provisioning dialogs do not apply RBAC filtering to resources displayed in dialog fields 1248329 - upstream:Copying an Analysis Profile shows Add screen, but no buttons are present 1248446 - Schedule editor not initializing Action drop down 1248547 - Add container provider screen - the credentials section has a misplaced "optional" label 1248747 - service :quota : Provisioning quota for CPU , Memory and Storage doesn't work 1248914 - upstream:undefined method `[]' for nil:NilClass [vm/right_size] on VM 'Right Size Recommendation' 1248951 - undefined method `include?' for nil:NilClass [catalog/x_button] on service catalog Add new button 1249664 - Dashboard "Top Storage Consumers" clickable but does not react on mouseover 1249670 - "[NameError]: uninitialized constant ManageIQ::Providers::Vmware::InfraManager::RefreshParser::Filter::Parser" found in evm.log file 1249692 - Error message should be shown when OpenStack Cloud added as OpenStack Infra provider 1249726 - Clicking on the Cloud Intelligence/Reports throws error in production.log file 1249730 - Running reports produces different errors each time 1250087 - Provisioning fails due to cluster not being selected on Vmware / RHEV 1250202 - Unable to see heat templates in tenants other than admin 1250229 - UI plugin for external links in CFME menu displays empty frame instead of configured external website 1250438 - UI: Clicking on refresh button in "All saved reports" page says "The user is not authorized for this task or item." 1250444 - Log directory filling up when AWS was having API issues 1250831 - [TypeError]#not a class/module Method:[rescue in deliver] during vmware snapshot creation 1251311 - Dashboard Graph widgets fail to load when revisiting the dashboard 1251345 - [TypeError] no implicit conversion of nil into String on Add/copy Infra/PXE customization templates 1251819 - No flash message displayed for validate for validate Foreman provider 1252672 - undefined method `super_admin_user?' for # [miq_ae_tools/resolve] in Automate->Simulation 1252678 - ActionController::RoutingError in database tab pages 1252849 - Heat stack deployment gets stuck when stack parameter is not found 1252976 - Service Dialog Import / Export isn't importing All of the Service Dialogs 1253126 - ERROR -- : PG::AmbiguousColumn: ERROR: column reference "ems_id" is ambiguous LINE 1: ..."event_streams".. in provider timelines 1253134 - (LoadError) cannot load such file -- workers/event_catcher_openstack on adding openstack provider 1253339 - Host Timeline results in infinite refresh with error in host and vm 1253442 - WebUI: Replace <_Unassigned> with in Catalog drop down 1253460 - WebUI: Center toolbar disappears after clicking on search button 1253463 - Sorting container entities list by provider column crashes the UI 1253468 - UI: Error when trying to access Cluster summary screen 1253479 - WebUI: Credential fields missing while adding new foreman provider 1254055 - Unable to add new fields in Automate Class Schema 1254058 - Automate Class Schema can't change sequence of fields 1254211 - when quota exceeds Group Allocated Memory always shows "0.00GB" in last message of request details page 1254302 - linux_admin dependency is too wide open causing failure in internal database configuration 1254359 - VM fails to launch on Amazon with NameError log_header 1254564 - SmartState times out if snapshot creation takes too long 1254882 - Provisioning quota for CPU/Mem/Storage doesn't work for cloud providers 1255048 - Reconfigure service button gives 404 1255190 - Vm Clone : Need ISO image selection validation when provision_type ISO is selected in cloning 1255485 - Web UI: "¶" string needs to be handled properly in Automate Instance 1256404 - Amazon provider fails with: [NoMethodError]: undefined method `keys' for nil:NilClass 1256437 - Protected text fields are not being added to options_hash 1256534 - Unexpected Error Encountered Refreshing Running Tasks 1256674 - The cursor inside the VM and outside the VM are not moving together for Win 7 or Win 2008. 1257748 - [RFE] Add the ability to change the password for a user through API, especially for 'admin' user 1258072 - UI: Bottleneck events for providers not seen under Optimize ->Bottlenecks 1258648 - State= running raised exception: 1258927 - UI: Reports explorer rebuilds trees on every transaction after Queue Report button is pressed once in UI. 1258985 - when a smartstate worker times out and is killed, any child processes (eg,vixdisklibserver.rb processes) are not killed with their parents leaving them running with PID 1 as the adopted parent process 1259082 - UI: Replace 'choose a clusters' with 'choose a cluster' on Optimize->Planning page 1260139 - IP Address of VMware host not found 1260196 - [RFE] Cloud Inventory collection should gather and store disk info for flavors 1260436 - Unable to deploy heat stack from bundle catalog item 1260640 - vnc connections to a windows 8.1/2012R2 experience mouse tracking issues 1262002 - Openstack Infrastructure provider shows Credentials in the Status box when AMQP credentials are provided 1262461 - Orchestration stack summary page show 0 number of instances, security groups, and networks 1262841 - Datastore File Browsing: Columns sorting does not work, per page change does not work 1262973 - Order service form shows