RHEL 6:cfme (RHSA-2014:1317)

medium Nessus Plugin ID 233047

概要

遠端 Red Hat 主機缺少一個或多個安全性更新。

說明

遠端 Redhat Enterprise Linux 6 主機上安裝的套件受到 RHSA-2014:1317 公告中提及的多個弱點影響。

Red Hat CloudForms Management Engine 提供因應管理虛擬環境挑戰所需的深入見解、控制機制及自動化服務。CloudForms Management Engine 建置在 Ruby on Rails 上,後者是一個適用於 Web 應用程式開發的模型檢視控制器 (MVC) 架構。
Action Pack 可實作控制器和檢視元件。

據發現,Red Hat CloudForms 會洩漏可透過 HTTP(S) 要求到達的預設路由。經驗證的使用者可利用此瑕疵存取可能允許特權提升的敏感控制器和動作。(CVE-2014-0140)

據發現,Red Hat CloudForms 包含已接受使用者提供引數的不安全傳送方法。經驗證的使用者可利用此瑕疵修改程式流程,進而導致特權提升。(CVE-2014-3642)

這些問題是由 Red Hat 產品安全性部門的 Jan Rusnacko 所發現。

此更新亦可修正數個錯誤,並新增數個增強功能。
這些變更的說明文件可從〈參照〉一節中的「發佈版本通知」與「技術提示」文件連結中取得。

建議所有 cfme 使用者皆升級至這些更新版套件,其可更正這些問題並新增這些增強功能。

Tenable 已直接從 Red Hat Enterprise Linux 安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

更新受影響的套件。

另請參閱

https://access.redhat.com/security/updates/classification/#moderate

http://www.nessus.org/u?98c0fbcd

http://www.nessus.org/u?ce39f374

https://bugzilla.redhat.com/show_bug.cgi?id=1077359

https://bugzilla.redhat.com/show_bug.cgi?id=1092894

http://www.nessus.org/u?bbf07b5c

https://access.redhat.com/errata/RHSA-2014:1317

Plugin 詳細資訊

嚴重性: Medium

ID: 233047

檔案名稱: redhat-RHSA-2014-1317.nasl

版本: 1.1

類型: local

代理程式: unix

已發布: 2025/3/20

已更新: 2025/3/20

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

風險資訊

VPR

風險因素: Medium

分數: 5.9

Vendor

Vendor Severity: Moderate

CVSS v2

風險因素: Medium

基本分數: 6.5

時間性分數: 4.8

媒介: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS 評分資料來源: CVE-2014-3642

CVSS v3

風險因素: Medium

基本分數: 6.5

時間性分數: 5.7

媒介: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

CVSS 評分資料來源: CVE-2014-0140

弱點資訊

CPE: p-cpe:/a:redhat:enterprise_linux:libipa_hbac-python, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simplecov-html, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-nokogiri, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruport, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-snmp, p-cpe:/a:redhat:enterprise_linux:libsss_nss_idmap-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-crack, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-pg, cpe:/o:redhat:enterprise_linux:6, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-handsoap, p-cpe:/a:redhat:enterprise_linux:sssd-client, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-active_hash, p-cpe:/a:redhat:enterprise_linux:libsss_idmap, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-arrayfields, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-main, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-trollop, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-platform, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-amq-protocol, p-cpe:/a:redhat:enterprise_linux:libipa_hbac-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-hmac, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubyrep, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-websocket, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rufus-scheduler, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-actionpack, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-actionwebservice, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-scp, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-open4, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-fattr, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-prototype-rails, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-code_analyzer, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-vcr, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-formatador, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rack-test, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-selenium-webdriver, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-more_core_extensions, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-colored, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-activerecord, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rdoc, p-cpe:/a:redhat:enterprise_linux:mingw32-cfme-host, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-binary_struct, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-core, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby-prof, p-cpe:/a:redhat:enterprise_linux:mod_authnz_pam, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-gssapi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-gyoku, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-wasabi, p-cpe:/a:redhat:enterprise_linux:cfme-lib, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-activeresource, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-color, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-flog, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simplecov-rcov-text, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-parallel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby2ruby, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-fastercsv, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-mocks, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-bullet, p-cpe:/a:redhat:enterprise_linux:python-sssdconfig, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-transaction-simple, p-cpe:/a:redhat:enterprise_linux:open-vm-tools-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-progressbar, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-addressable, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-json_pure, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-railties, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-secure_headers, p-cpe:/a:redhat:enterprise_linux:mod_intercept_form_submit, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-flay, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simplecov-rcov, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-princely, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-bundler_ext, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-rails, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-xml-simple, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-inifile, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubyzip, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ziya, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-savon, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ezcrypto, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-fire, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-american_date, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-haml-rails, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-i18n, p-cpe:/a:redhat:enterprise_linux:mod_lookup_identity, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-hoe, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-jbuilder, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-test-unit, p-cpe:/a:redhat:enterprise_linux:sssd-proxy, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-ldap, p-cpe:/a:redhat:enterprise_linux:libdnet, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-ping, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-sftp, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-qpid_messaging, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-shoulda-matchers, p-cpe:/a:redhat:enterprise_linux:cfme-appliance, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-mime-types, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rails, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-minitest, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rbovirt, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-httparty, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simple-rss, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-eventmachine, p-cpe:/a:redhat:enterprise_linux:libdnet-progs, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubyntlm, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-excon, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-childprocess, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-webmock, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-actionmailer, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rake, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-uglifier, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-uniform_notifier, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-map, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-syntax, p-cpe:/a:redhat:enterprise_linux:sssd-common-pac, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-hirb, p-cpe:/a:redhat:enterprise_linux:sssd-tools, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-bunny, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-outfielding-jqplot-rails, p-cpe:/a:redhat:enterprise_linux:sssd-ad, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby_parser, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-terminal-table, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-haml, p-cpe:/a:redhat:enterprise_linux:prince, p-cpe:/a:redhat:enterprise_linux:sneakernet_ca, p-cpe:/a:redhat:enterprise_linux:cfme-vnc-plugin, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ancestry, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubyforge, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-linux_admin, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-netrc, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rest-client, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-awesome_print, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-reek, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec-expectations, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-timecop, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-activesupport, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-elif, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby-progressbar, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-awesome_spawn, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-aws-sdk, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-shindo, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-winrm, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-brakeman, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-libxml-ruby, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-log4r, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-mail, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-slim, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby-plsql, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-httpi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-sexp_processor, p-cpe:/a:redhat:enterprise_linux:lshw, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-roodi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rufus-lru, p-cpe:/a:redhat:enterprise_linux:sssd-ldap, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-chronic, p-cpe:/a:redhat:enterprise_linux:libsss_nss_idmap-python, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-fog, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-httpclient, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-multi_json, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-soap4r, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ffi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-churn, p-cpe:/a:redhat:enterprise_linux:sssd-krb5-common, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rubywbem, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-akami, p-cpe:/a:redhat:enterprise_linux:cfme, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-capybara, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-xpath, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-nori, p-cpe:/a:redhat:enterprise_linux:libsss_nss_idmap, p-cpe:/a:redhat:enterprise_linux:sssd, p-cpe:/a:redhat:enterprise_linux:libdnet-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-acts_as_tree, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-daemons, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rails_best_practices, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-thin, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-net-ssh, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-little-plugger, p-cpe:/a:redhat:enterprise_linux:netapp-manageability-sdk-devel, p-cpe:/a:redhat:enterprise_linux:libipa_hbac, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-dalli, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-japgolly-saikuro, p-cpe:/a:redhat:enterprise_linux:netapp-manageability-sdk, p-cpe:/a:redhat:enterprise_linux:selinux-policy, p-cpe:/a:redhat:enterprise_linux:open-vm-tools-desktop, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-simplecov, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-default_value_for, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-test-spec, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-io-extra, p-cpe:/a:redhat:enterprise_linux:certmonger, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-uuidtools, p-cpe:/a:redhat:enterprise_linux:pyliblzma, p-cpe:/a:redhat:enterprise_linux:sssd-krb5, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-factory_girl, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-state_machine, p-cpe:/a:redhat:enterprise_linux:sssd-dbus, p-cpe:/a:redhat:enterprise_linux:sssd-common, p-cpe:/a:redhat:enterprise_linux:lshw-gui, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-acts_as_list, p-cpe:/a:redhat:enterprise_linux:libsss_idmap-devel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ruby-graphviz, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-ovirt_metrics, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-highline, p-cpe:/a:redhat:enterprise_linux:sssd-ipa, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-logging, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-execjs, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-pdf-writer, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-temple, p-cpe:/a:redhat:enterprise_linux:selinux-policy-targeted, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-multi_xml, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rspec, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rbvmomi, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rack, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-json, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-facade, p-cpe:/a:redhat:enterprise_linux:open-vm-tools, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-metric_fu, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-activemodel, p-cpe:/a:redhat:enterprise_linux:ruby193-rubygem-rake-compiler

必要的 KB 項目: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2014/10/2

弱點發布日期: 2014/10/2

參考資訊

CVE: CVE-2014-0140, CVE-2014-3642

CWE: 470, 749

RHSA: 2014:1317