6.8
CVE-2014-0152
- EPSS 1.76%
- Veröffentlicht 08.09.2014 14:55:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Ovirt-engine Version 3.0.0
Redhat ≫ Ovirt-engine Version 3.1.0
Redhat ≫ Ovirt-engine Version 3.2.0
Redhat ≫ Ovirt-engine Version 3.3.0
Redhat ≫ Ovirt-engine Version 3.3.2 Update rc1
Redhat ≫ Ovirt-engine Version 3.3.3
Redhat ≫ Ovirt-engine Version 3.3.4
Redhat ≫ Ovirt-engine Version 3.3.5
Redhat ≫ Ovirt-engine Version 3.4.0 Update rc1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.76% | 0.75 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://gerrit.ovirt.org/#/c/25959/
http://www.ovirt.org/Security_advisories