CVE Vulnerabilities

CVE-2019-3831

Published: Mar 25, 2019 | Modified: Oct 19, 2020
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root.

Affected Software

Name Vendor Start Version End Version
Vdsm Ovirt 4.19 (including) 4.30.3 (including)
Vdsm Ovirt 4.30.5 (including) 4.30.8 (including)

References