Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ovirt Engine HIGH 7.5
CVE-2024-0822

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to …

Patch available
Fix from $1,950 2024-01-25
Ovirt Engine MEDIUM 6.1
CVE-2022-3193

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize…

Mitigation only
Fix from $1,600 2022-09-28
Ovirt Engine MEDIUM 6.1
CVE-2020-14333

A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting…

Fix: after 4.4.0
Fix from $1,600 2020-08-18
Node HIGH 7.8
CVE-2013-0293

oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation

Mitigation only
Fix from $1,950 2019-12-10
Vdsm HIGH 7.5
CVE-2012-5518

vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)

Mitigation only
Fix from $1,950 2019-11-25
Ovirt Engine HIGH 7.8
CVE-2013-4367

ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how pyth…

Patch available
Fix from $1,950 2019-11-01
Cockpit Ovirt HIGH 7.8
CVE-2019-10139

During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXX…

Mitigation only
Fix from $1,950 2019-05-17
Ovirt HIGH 7.8
CVE-2018-1075

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one choo…

Fix: 4.2.3+
Fix from $1,950 2018-06-12
Ovirt Hosted Engine Setup HIGH 7.8
CVE-2018-1000018

An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.

Fix: 2.2.7+
Fix from $1,950 2018-01-24
Ovirt Node HIGH 8.8
CVE-2014-8170

ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virt…

Mitigation only
Fix from $1,950 2017-09-26
Ovirt MEDIUM 5.5
CVE-2016-6341

oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive pas…

Fix: after 4.0.2
Fix from $1,600 2017-04-20
Ovirt MEDIUM 5.0
CVE-2014-0154

oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers t…

Fix: after 3.4.4
Fix from $1,600 2015-02-13
Ovirt MEDIUM 5.0
CVE-2012-3533

The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows re…

Fix: after 3.1.0.5
Fix from $1,600 2012-08-31