Ovirt Engine Ovirt Engine

Do you want an email whenever new security vulnerabilities are reported in Ovirt Engine?

By the Year

In 2024 there have been 1 vulnerability in Ovirt Engine with an average score of 7.5 out of ten. Ovirt Engine did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2024 as compared to last year.

Year Vulnerabilities Average Score
2024 1 7.50
2023 0 0.00
2022 2 6.95
2021 0 0.00
2020 3 6.23
2019 0 0.00
2018 0 0.00

It may take a day or so for new Ovirt Engine vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Ovirt Engine Security Vulnerabilities

An authentication bypass vulnerability was found in overt-engine

CVE-2024-0822 7.5 - High - January 25, 2024

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.

authentification

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine

CVE-2022-3193 6.1 - Medium - September 28, 2022

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

XSS

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values

CVE-2022-0847 7.8 - High - March 10, 2022

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

Improper Initialization

A flaw was found in ovirt-engine 4.4.3 and earlier

CVE-2020-35497 6.5 - Medium - December 21, 2020

A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.

Authorization

A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier

CVE-2020-14333 6.1 - Medium - August 18, 2020

A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting in a reflected cross-site scripting attack. This flaw allows an attacker to leverage a phishing attack, steal an unsuspecting user's cookies or other confidential information, or impersonate them within the application's context.

XSS

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8

CVE-2019-19336 6.1 - Medium - March 19, 2020

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Red Hat Virtualization or by Ovirt? Click the Watch button to subscribe.

Ovirt
Vendor

Ovirt Engine
Product

subscribe