Skip to main content

Vendor/product archive

ovirt / ovirt-engine CVEs

Beta · best-effort

9 CVEs tagged to ovirt / ovirt-engine0 Critical, 3 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-7259

Published Sep 26, 2024

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider pas…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0822

Published Jan 25, 2024

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSessio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3193

Published Sep 28, 2022

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulne…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14333

Published Aug 18, 2020

A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting in a reflected cross-site scr…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19336

Published Mar 19, 2020

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response withou…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4367

Published Nov 1, 2019

ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when pas…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1