Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2018-1073

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
Attacker Value
Unknown

CVE-2018-1075

Disclosure Date: June 12, 2018 (last updated November 26, 2024)
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
0
Attacker Value
Unknown

CVE-2018-1074

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
0
Attacker Value
Unknown

CVE-2018-1000095

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
0
Attacker Value
Unknown

CVE-2018-1062

Disclosure Date: March 06, 2018 (last updated November 26, 2024)
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later allocated to a new disk attached to another VM, potentially sensitive data could be revealed to privileged users of that VM.
Attacker Value
Unknown

CVE-2018-1000018

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
0
Attacker Value
Unknown

CVE-2014-7851

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.
0
Attacker Value
Unknown

CVE-2014-8170

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.
0
Attacker Value
Unknown

CVE-2016-3113

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
Attacker Value
Unknown

CVE-2016-3077

Disclosure Date: June 06, 2017 (last updated November 26, 2024)
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.
0