{
  "threat_severity" : "Moderate",
  "public_date" : "2018-03-21T00:00:00Z",
  "bugzilla" : {
    "description" : "rubygem-rails-html-sanitizer: non-whitelisted attributes are present in sanitized output when input with specially-crafted HTML fragments leading to XSS vulnerability",
    "id" : "1568842",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1568842"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.1",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-79",
  "details" : [ "There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately." ],
  "statement" : "This issue affects the versions of rubygem-rails-html-sanitizer as shipped with Red Hat CloudForms 4. Red Hat Product Security has rated this issue as having a security  impact of Moderate. This vulnerability won't be fixed on CloudForms 4, because it uses libxml 2.9.1 and since the vulnerability requires a libxml >= 2.9.2 in order to be exploitable. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/",
  "affected_release" : [ {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ansible-runner-0:1.1.2-2.el7ar"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ansible-tower-0:3.3.3-1.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "bubblewrap-0:0.1.7-1.el7"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "cfme-0:5.10.0.33-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "cfme-amazon-smartstate-0:5.10.0.33-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "cfme-appliance-0:5.10.0.33-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "cfme-gemset-0:5.10.0.33-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "dbus-api-service-0:1.0.1-5.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "dumb-init-0:1.2.0-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "erlang-0:19.3.6.7-1.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "google-compute-engine-0:2.0.0-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "google-config-0:2.0.0-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "httpd-configmap-generator-0:0.2.2-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "nginx-1:1.10.2-1.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-cluster-upgrade-0:1.1.8-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-disaster-recovery-0:1.1.2-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-engine-setup-0:1.1.5-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-image-template-0:1.1.8-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-infra-0:1.1.8-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-manageiq-0:1.1.12-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-repositories-0:1.1.2-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-roles-0:1.1.5-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-shutdown-env-0:1.0.0-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-v2v-conversion-host-0:1.6.3-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ovirt-ansible-vm-infra-0:1.1.10-1.el7ev"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "postgresql96-0:9.6.10-1PGDG.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "prince-0:9.0r2-10.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "pyOpenSSL-0:17.3.0-4.el7ost"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-bambou-0:3.0.1-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-colorama-0:0.3.7-2.el7ost"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-crypto-0:2.6.1-16.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-daemon-0:2.1.2-7.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-funcsigs-0:1.0.2-1.el7ost"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-future-0:0.16.0-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-lockfile-1:0.11.0-10.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-meld3-0:0.6.10-1.el7"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-mock-0:2.0.0-1.el7ost"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-pbr-0:3.1.1-2.el7ost"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-pexpect-0:4.6-1.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-psutil-0:5.4.3-2.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-ptyprocess-0:0.5.2-3.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-pylxca-0:2.1.1-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-pysocks-0:1.5.6-3.el7ost"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-requests-0:2.14.2-1.el7ost"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-requests-toolbelt-0:0.8.0-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-tabulate-0:0.8.2-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-urllib3-0:1.21.1-1.2.el7ost"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "python-vspk-0:5.3.2-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "qpid-proton-0:0.19.0-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rabbitmq-server-0:3.7.4-1.el7at"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rh-postgresql95-postgresql-pglogical-0:2.1.0-4.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rh-postgresql95-repmgr-0:4.0.6-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "ruby-0:2.4.5-90.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-bcrypt-0:3.1.12-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-ffi-0:1.9.25-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-hamlit-0:2.8.8-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-http_parser.rb-0:0.6.0-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-json-0:2.1.0-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-linux_block_device-0:0.2.1-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-memory_buffer-0:0.1.0-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-nio4r-0:2.3.1-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-nokogiri-0:1.8.2-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-ovirt-engine-sdk4-0:4.2.4-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-pg-0:0.18.4-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-puma-0:3.7.1-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-qpid_proton-0:0.22.0-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-redhat_access_cfme-0:2.0.3-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-redhat_access_lib-0:1.1.4-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-rugged-0:0.27.4-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-sqlite3-0:1.3.13-2.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-unf_ext-0:0.0.7.5-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "rubygem-websocket-driver-0:0.6.5-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "smem-0:1.4-1.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "supervisor-0:3.1.4-1.el7"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "wmi-0:1.3.14-7.el7cf"
  }, {
    "product_name" : "CloudForms Management Engine 5.10",
    "release_date" : "2019-02-07T00:00:00Z",
    "advisory" : "RHSA-2019:0212",
    "cpe" : "cpe:/a:redhat:cloudforms_managementengine:5.10::el7",
    "package" : "wxGTK3-0:3.0.3-5.el7at"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Will not fix",
    "package_name" : "rh-ror42-rubygem-rails-html-sanitizer",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:3"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Will not fix",
    "package_name" : "rh-ror50-rubygem-rails-html-sanitizer",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2018-3741\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-3741" ],
  "name" : "CVE-2018-3741",
  "csaw" : false
}