RHEL 6:cfme (RHSA-2014:1317)

medium Nessus 插件 ID 233047

简介

远程 Red Hat 主机缺少一个或多个安全更新。

描述

远程 Redhat Enterprise Linux 6 主机上安装的程序包受到 RHSA-2014:1317 公告中提及的多个漏洞的影响。

Red Hat CloudForms Management Engine 提供可解决管理虚拟环境难题所需的见解、控件和自动化。CloudForms Management Engine 基于 Ruby on Rails 构建,后者是适用于 Web 应用程序开发的模型-视图-控制器 (MVC) 框架。
Action Pack 实施控制器和视图组件。

已发现 Red Hat CloudForms 会暴露可通过 HTTP(S) 请求访问的默认路由。经过认证的用户可利用此缺陷,访问可能敏感的控制器和操作,这将允许权限升级。(CVE-2014-0140)

已发现 Red Hat CloudForms 包含不安全的 send 方法,该方法接受用户提供的参数。经过认证的用户可利用此缺陷修改程序流,其方式可导致权限升级。(CVE-2014-3642)

问题由 Red Hat 产品安全团队的 Jan Rusnacko 发现。

此更新还修复了多个缺陷并添加了多项增强功能。
“参考”部分链接的发行说明和技术札记文档中提供这些更改的文档。

建议所有 cfme 用户升级这些更新后的程序包,其中修正了这些问题并添加这些增强。

Tenable 已直接从 Red Hat Enterprise Linux 安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

更新受影响的程序包。

另见

https://access.redhat.com/security/updates/classification/#moderate

http://www.nessus.org/u?98c0fbcd

http://www.nessus.org/u?ce39f374

https://bugzilla.redhat.com/show_bug.cgi?id=1077359

https://bugzilla.redhat.com/show_bug.cgi?id=1092894

http://www.nessus.org/u?bbf07b5c

https://access.redhat.com/errata/RHSA-2014:1317

插件详情

严重性: Medium

ID: 233047

文件名: redhat-RHSA-2014-1317.nasl

版本: 1.1

类型: local

代理: unix

发布时间: 2025/3/20

最近更新时间: 2025/3/20

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

风险信息

VPR

风险因素: Medium

分数: 5.9

Vendor

Vendor Severity: Moderate

CVSS v2

风险因素: Medium

基本分数: 6.5

时间分数: 4.8

矢量: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS 分数来源: CVE-2014-3642

CVSS v3

风险因素: Medium

基本分数: 6.5

时间分数: 5.7

矢量: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

CVSS 分数来源: CVE-2014-0140

漏洞信息

CPE: p-cpe:/a:redhat:enterprise_linux:libipa_hbac-python, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simplecov-html, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-nokogiri, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruport, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-snmp, p-cpe:/a:redhat:enterprise_linux:libsss_nss_idmap-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-crack, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-pg, cpe:/o:redhat:enterprise_linux:6, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-handsoap, p-cpe:/a:redhat:enterprise_linux:sssd-client, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-active_hash, p-cpe:/a:redhat:enterprise_linux:libsss_idmap, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-arrayfields, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-main, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-trollop, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-platform, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-amq-protocol, p-cpe:/a:redhat:enterprise_linux:libipa_hbac-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-hmac, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubyrep, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-websocket, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rufus-scheduler, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-actionpack, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-actionwebservice, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-scp, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-open4, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-fattr, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-prototype-rails, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-code_analyzer, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-vcr, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-formatador, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rack-test, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-selenium-webdriver, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-more_core_extensions, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-colored, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-activerecord, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rdoc, p-cpe:/a:redhat:enterprise_linux:mingw32-cfme-host, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-binary_struct, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-core, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby-prof, p-cpe:/a:redhat:enterprise_linux:mod_authnz_pam, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-gssapi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-gyoku, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-wasabi, p-cpe:/a:redhat:enterprise_linux:cfme-lib, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-activeresource, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-color, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-flog, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simplecov-rcov-text, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-parallel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby2ruby, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-fastercsv, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-mocks, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-bullet, p-cpe:/a:redhat:enterprise_linux:python-sssdconfig, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-transaction-simple, p-cpe:/a:redhat:enterprise_linux:open-vm-tools-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-progressbar, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-addressable, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-json_pure, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-railties, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-secure_headers, p-cpe:/a:redhat:enterprise_linux:mod_intercept_form_submit, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-flay, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simplecov-rcov, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-princely, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-bundler_ext, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-rails, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-xml-simple, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-inifile, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubyzip, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ziya, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-savon, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ezcrypto, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-fire, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-american_date, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-haml-rails, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-i18n, p-cpe:/a:redhat:enterprise_linux:mod_lookup_identity, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-hoe, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-jbuilder, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-test-unit, p-cpe:/a:redhat:enterprise_linux:sssd-proxy, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-ldap, p-cpe:/a:redhat:enterprise_linux:libdnet, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-ping, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-sftp, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-qpid_messaging, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-shoulda-matchers, p-cpe:/a:redhat:enterprise_linux:cfme-appliance, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-mime-types, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rails, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-minitest, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rbovirt, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-httparty, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simple-rss, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-eventmachine, p-cpe:/a:redhat:enterprise_linux:libdnet-progs, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubyntlm, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-excon, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-childprocess, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-webmock, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-actionmailer, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rake, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-uglifier, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-uniform_notifier, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-map, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-syntax, p-cpe:/a:redhat:enterprise_linux:sssd-common-pac, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-hirb, p-cpe:/a:redhat:enterprise_linux:sssd-tools, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-bunny, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-outfielding-jqplot-rails, p-cpe:/a:redhat:enterprise_linux:sssd-ad, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby_parser, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-terminal-table, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-haml, p-cpe:/a:redhat:enterprise_linux:prince, p-cpe:/a:redhat:enterprise_linux:sneakernet_ca, p-cpe:/a:redhat:enterprise_linux:cfme-vnc-plugin, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ancestry, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubyforge, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-linux_admin, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-netrc, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rest-client, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-awesome_print, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-reek, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-expectations, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-timecop, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-activesupport, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-elif, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby-progressbar, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-awesome_spawn, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-aws-sdk, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-shindo, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-winrm, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-brakeman, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-libxml-ruby, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-log4r, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-mail, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-slim, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby-plsql, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-httpi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-sexp_processor, p-cpe:/a:redhat:enterprise_linux:lshw, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-roodi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rufus-lru, p-cpe:/a:redhat:enterprise_linux:sssd-ldap, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-chronic, p-cpe:/a:redhat:enterprise_linux:libsss_nss_idmap-python, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-fog, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-httpclient, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-multi_json, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-soap4r, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ffi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-churn, p-cpe:/a:redhat:enterprise_linux:sssd-krb5-common, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubywbem, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-akami, p-cpe:/a:redhat:enterprise_linux:cfme, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-capybara, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-xpath, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-nori, p-cpe:/a:redhat:enterprise_linux:libsss_nss_idmap, p-cpe:/a:redhat:enterprise_linux:sssd, p-cpe:/a:redhat:enterprise_linux:libdnet-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-acts_as_tree, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-daemons, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rails_best_practices, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-thin, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-ssh, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-little-plugger, p-cpe:/a:redhat:enterprise_linux:netapp-manageability-sdk-devel, p-cpe:/a:redhat:enterprise_linux:libipa_hbac, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-dalli, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-japgolly-saikuro, p-cpe:/a:redhat:enterprise_linux:netapp-manageability-sdk, p-cpe:/a:redhat:enterprise_linux:selinux-policy, p-cpe:/a:redhat:enterprise_linux:open-vm-tools-desktop, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simplecov, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-default_value_for, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-test-spec, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-io-extra, p-cpe:/a:redhat:enterprise_linux:certmonger, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-uuidtools, p-cpe:/a:redhat:enterprise_linux:pyliblzma, p-cpe:/a:redhat:enterprise_linux:sssd-krb5, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-factory_girl, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-state_machine, p-cpe:/a:redhat:enterprise_linux:sssd-dbus, p-cpe:/a:redhat:enterprise_linux:sssd-common, p-cpe:/a:redhat:enterprise_linux:lshw-gui, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-acts_as_list, p-cpe:/a:redhat:enterprise_linux:libsss_idmap-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby-graphviz, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ovirt_metrics, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-highline, p-cpe:/a:redhat:enterprise_linux:sssd-ipa, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-logging, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-execjs, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-pdf-writer, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-temple, p-cpe:/a:redhat:enterprise_linux:selinux-policy-targeted, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-multi_xml, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rbvmomi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rack, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-json, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-facade, p-cpe:/a:redhat:enterprise_linux:open-vm-tools, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-metric_fu, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-activemodel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rake-compiler

必需的 KB 项: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

易利用性: No known exploits are available

补丁发布日期: 2014/10/2

漏洞发布日期: 2014/10/2

参考资料信息

CVE: CVE-2014-0140, CVE-2014-3642

CWE: 470, 749

RHSA: 2014:1317