Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_virtualization_manager | Redhat | * | 3.5.0 (including) |
RHEV Manager version 3.5 | RedHat | org.ovirt.engine-root-0:3.5.1-4 | * |