Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ovirt | Ovirt | * | 3.4.0 (including) |
Ovirt-engine | Redhat | 3.0.0 (including) | 3.0.0 (including) |
Ovirt-engine | Redhat | 3.1.0 (including) | 3.1.0 (including) |
Ovirt-engine | Redhat | 3.2.0 (including) | 3.2.0 (including) |
Ovirt-engine | Redhat | 3.3.0 (including) | 3.3.0 (including) |
Ovirt-engine | Redhat | 3.3.2-rc1 (including) | 3.3.2-rc1 (including) |
Ovirt-engine | Redhat | 3.3.3 (including) | 3.3.3 (including) |
Ovirt-engine | Redhat | 3.3.4 (including) | 3.3.4 (including) |
Ovirt-engine | Redhat | 3.3.5 (including) | 3.3.5 (including) |
Ovirt-engine | Redhat | 3.4.0-rc1 (including) | 3.4.0-rc1 (including) |
RHEV Manager version 3.4 | RedHat | org.ovirt.engine-root-0:3.4.0-21 | * |