Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_virtualization_manager | Redhat | * | 3.5.0 (including) |
RHEV Manager version 3.5 | RedHat | org.ovirt.engine-root-0:3.5.1-4 | * |