← Back

CVE-2014-8170

nvd nist
Published: Sep 26, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.

Affected (1)

Products: Ovirt: Ovirt Node
1 product
Ovirt Node
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.0.0-474-gb852fd7
Running on/withPlatform Versions
Redhat
Enterprise Virtualization
Version 3.0

Timeline

No history available yet.