VYPR

oVirt

by Red Hat

CVEs (3)

  • CVE-2019-10139HigMay 17, 2019
    risk 0.51cvss 7.8epss 0.00

    During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are…

  • CVE-2015-1780MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.01

    oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center

  • CVE-2024-0822HigJan 25, 2024
    risk 0.00cvss 7.5epss 0.01

    An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.