CVE Vulnerabilities

CVE-2014-0152

Published: Sep 08, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu

Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Ovirt Ovirt * 3.4.0 (including)
Ovirt-engine Redhat 3.0.0 (including) 3.0.0 (including)
Ovirt-engine Redhat 3.1.0 (including) 3.1.0 (including)
Ovirt-engine Redhat 3.2.0 (including) 3.2.0 (including)
Ovirt-engine Redhat 3.3.0 (including) 3.3.0 (including)
Ovirt-engine Redhat 3.3.2-rc1 (including) 3.3.2-rc1 (including)
Ovirt-engine Redhat 3.3.3 (including) 3.3.3 (including)
Ovirt-engine Redhat 3.3.4 (including) 3.3.4 (including)
Ovirt-engine Redhat 3.3.5 (including) 3.3.5 (including)
Ovirt-engine Redhat 3.4.0-rc1 (including) 3.4.0-rc1 (including)
RHEV Manager version 3.4 RedHat org.ovirt.engine-root-0:3.4.0-21 *

References