Vulnerabilities
Vulnerable Software
Redhat:  >> Ovirt-Engine  >> 3.3  Security Vulnerabilities
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.
CVSS Score
5.3
EPSS Score
0.002
Published
2020-08-24
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.
CVSS Score
7.5
EPSS Score
0.004
Published
2017-10-16
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
CVSS Score
6.8
EPSS Score
0.001
Published
2015-02-13


Contact Us

Shodan ® - All rights reserved