Ovirt
Ovirt-engine: vulnerabilidades y CVE
Ovirt-engine tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0847 | Alta (7.8) | 93% | ⚠ Explotación activa | 10 mar 2022 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-7259 | Media (4.9) | 0.26% | — | 26 sept 2024 | A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext. |
| CVE-2024-0822 | Alta (7.5) | 0.71% | — | 25 ene 2024 | An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command. |
| CVE-2022-3193 | Media (6.1) | 0.50% | — | 28 sept 2022 | An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows… |
| CVE-2022-0847 | Alta (7.8) | 93% | ⚠ Explotación activa | 10 mar 2022 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale… |
| CVE-2020-35497 | Media (6.5) | 0.76% | — | 21 dic 2020 | A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key. |
| CVE-2020-14333 | Media (6.1) | 0.79% | — | 18 ago 2020 | A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting in a reflected cross-site scripting attack. This flaw allows an… |
| CVE-2019-19336 | Media (6.1) | 0.96% | — | 19 mar 2020 | A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an… |
| CVE-2013-4367 | Alta (7.8) | 0.32% | — | 1 nov 2019 | ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'. |
| CVE-2018-1073 | Media (5.3) | 1.9% | — | 19 jun 2018 | The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.