CVE Vulnerabilities

CVE-2019-3831

Published: Mar 25, 2019 | Modified: Oct 19, 2020
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
6.4 MODERATE
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Ubuntu

A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root.

Affected Software

Name Vendor Start Version End Version
Vdsm Ovirt 4.19 (including) 4.30.3 (including)
Vdsm Ovirt 4.30.5 (including) 4.30.8 (including)
Red Hat Gluster Storage 3.4 for RHEL 7 RedHat ioprocess-0:1.1.2-1.el7ev *
Red Hat Gluster Storage 3.4 for RHEL 7 RedHat safelease-0:1.0-7.el7ev *
Red Hat Gluster Storage 3.4 for RHEL 7 RedHat vdsm-0:4.30.18-1.0.el7rhgs *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat redhat-release-virtualization-host-0:4.2-8.3.el7 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat redhat-virtualization-host-0:4.2-20190219.0.el7_6 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat vdsm-0:4.20.47-1.el7ev *

References