Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2017-7510

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
Attacker Value
Unknown

CVE-2018-1073

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
Attacker Value
Unknown

CVE-2018-1000095

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
0
Attacker Value
Unknown

CVE-2018-1062

Disclosure Date: March 06, 2018 (last updated November 26, 2024)
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later allocated to a new disk attached to another VM, potentially sensitive data could be revealed to privileged users of that VM.
Attacker Value
Unknown

CVE-2018-1000018

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
0
Attacker Value
Unknown

CVE-2014-7851

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.
0
Attacker Value
Unknown

CVE-2016-3113

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
Attacker Value
Unknown

CVE-2016-3077

Disclosure Date: June 06, 2017 (last updated November 26, 2024)
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.
0
Attacker Value
Unknown

CVE-2014-0151

Disclosure Date: February 13, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
0
Attacker Value
Unknown

CVE-2014-0152

Disclosure Date: September 08, 2014 (last updated October 05, 2023)
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
0