CVE-2024-7259
- EPSS 0.06%
- Published 26.09.2024 16:15:08
- Last modified 30.07.2025 15:46:46
A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.
CVE-2020-10775
- EPSS 0.22%
- Published 24.08.2020 17:15:10
- Last modified 21.11.2024 04:56:02
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, ...
CVE-2015-1780
- EPSS 0.25%
- Published 22.11.2019 15:15:10
- Last modified 21.11.2024 02:26:06
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
CVE-2017-7510
- EPSS 0.25%
- Published 25.03.2019 18:29:00
- Last modified 21.11.2024 03:32:02
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
CVE-2018-1000095
- EPSS 0.22%
- Published 13.03.2018 01:29:00
- Last modified 21.11.2024 03:39:38
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
CVE-2018-1062
- EPSS 0.43%
- Published 06.03.2018 15:29:00
- Last modified 21.11.2024 03:59:05
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage bl...
CVE-2014-7851
- EPSS 0.39%
- Published 16.10.2017 15:29:00
- Last modified 20.04.2025 01:37:25
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token wi...
CVE-2016-3113
- EPSS 4.03%
- Published 07.08.2017 20:29:01
- Last modified 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
CVE-2016-3077
- EPSS 0.39%
- Published 06.06.2017 18:29:00
- Last modified 20.04.2025 01:37:25
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.
CVE-2014-0151
- EPSS 0.13%
- Published 13.02.2015 15:59:01
- Last modified 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.