Medium severity4.3NVD Advisory· Published Jun 14, 2019· Updated Jun 17, 2026
CVE-2019-10159
CVE-2019-10159
Description
cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:cfme-gemset:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:cfme-gemset:*:*:*:*:*:*:*:*range: >=5.9.0.22,<=5.9.9.3
- (no CPE)range: <=5.10.4.3, <=5.9.9.3
- cpe:2.3:a:redhat:cloudforms:4.7:*:*:*:*:*:*:*
- Red Hat/cfmev5Range: 5.10.4.3 and below, 5.9.9.3 and below
Patches
Vulnerability mechanics
References
2- access.redhat.com/errata/RHSA-2019:2466nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.