CVE Vulnerabilities

CVE-2014-7851

Published: Oct 16, 2017 | Modified: Feb 13, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another users session data to gain that users privileges by replacing their session token with that of another user.

Affected Software

Name Vendor Start Version End Version
Ovirt Ovirt 3.3.2 3.3.2
Ovirt Ovirt 3.4.0 3.4.0
Ovirt-engine Redhat 3.2.2 3.2.2
Ovirt-engine Redhat 3.3 3.3
Ovirt-engine Redhat 3.3 3.3
Ovirt-engine Redhat 3.3 3.3
Ovirt-engine Redhat 3.3.0.1 3.3.0.1
Ovirt-engine Redhat 3.3.1 3.3.1
Ovirt-engine Redhat 3.3.1 3.3.1
Ovirt-engine Redhat 3.3.1 3.3.1
Ovirt-engine Redhat 3.3.2 3.3.2
Ovirt-engine Redhat 3.3.3 3.3.3
Ovirt-engine Redhat 3.3.3 3.3.3
Ovirt-engine Redhat 3.3.4 3.3.4
Ovirt-engine Redhat 3.3.4 3.3.4
Ovirt-engine Redhat 3.3.5 3.3.5
Ovirt-engine Redhat 3.4.0 3.4.0
Ovirt-engine Redhat 3.4.0 3.4.0
Ovirt-engine Redhat 3.4.0 3.4.0
Ovirt-engine Redhat 3.4.0 3.4.0
Ovirt-engine Redhat 3.4.0 3.4.0
Ovirt-engine Redhat 3.4.1 3.4.1
Ovirt-engine Redhat 3.4.1 3.4.1
Ovirt-engine Redhat 3.4.2 3.4.2
Ovirt-engine Redhat 3.4.2 3.4.2
Ovirt-engine Redhat 3.4.3 3.4.3
Ovirt-engine Redhat 3.4.3 3.4.3
Ovirt-engine Redhat 3.4.4 3.4.4
Ovirt-engine Redhat 3.4.4 3.4.4
Ovirt-engine Redhat 3.5.0 3.5.0

References