Ovirt

Ovirt-engine

9 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 26.09.2024 16:15:08
  • Last modified 30.07.2025 15:46:46

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.

Exploit
  • EPSS 0.05%
  • Published 25.01.2024 16:15:08
  • Last modified 21.11.2024 08:47:26

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.

  • EPSS 0.84%
  • Published 28.09.2022 19:15:09
  • Last modified 20.05.2025 21:15:22

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

Warning Exploit
  • EPSS 83.71%
  • Published 10.03.2022 17:44:57
  • Last modified 30.07.2025 19:10:07

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user co...

  • EPSS 0.32%
  • Published 21.12.2020 17:15:12
  • Last modified 21.11.2024 05:27:25

A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.

  • EPSS 0.29%
  • Published 18.08.2020 14:15:12
  • Last modified 21.11.2024 05:03:01

A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting in a reflected cross-site scripting attack. This flaw allows an attacker to leverage a phishing atta...

  • EPSS 0.31%
  • Published 19.03.2020 14:15:11
  • Last modified 21.11.2024 04:34:36

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML p...

  • EPSS 0.11%
  • Published 01.11.2019 18:15:11
  • Last modified 21.11.2024 01:55:26

ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.

  • EPSS 0.27%
  • Published 19.06.2018 12:29:00
  • Last modified 21.11.2024 03:59:07

The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.