CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ovirt Redhat4Vdsm VirtualizationVirtualization For Ibm Power Little Endian+1 moreJun 17, 2026 Aug 26, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text. |
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate) |
2Ovirt Redhat2Gluster Storage VdsmJun 17, 2026 Mar 25, 2019 N/A· v4 6.7 MEDIUM· v3 9.0 HIGH· v2 A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root. |
2Ovirt Redhat2Vdsm VirtualizationNov 21, 2024 Aug 9, 2018 N/A· v4 6.3 MEDIUM· v3 7.1 HIGH· v2 It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amo...Show more |