By the Year
In 2022 there have been 0 vulnerabilities in Ovirt Engine . Ovirt Engine did not have any published security vulnerabilities last year.
It may take a day or so for new Ovirt Engine vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Ovirt Engine Security Vulnerabilities
A flaw was found in ovirt-engine 4.4.3 and earlier
6.5 - Medium
- December 21, 2020
A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.
A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier
6.1 - Medium
- August 18, 2020
A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting in a reflected cross-site scripting attack. This flaw allows an attacker to leverage a phishing attack, steal an unsuspecting user's cookies or other confidential information, or impersonate them within the application's context.
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8
6.1 - Medium
- March 19, 2020
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.