← Back

Ovirt

ovirt

34 CVEs • 12 products

Products (12)

Click to collapse
Toggle
Ovirt
ovirt
Ovirt Engine
ovirt-engine
Vdsm
vdsm
Node
node
Sanlock
sanlock
Ovirt Node
ovirt-node
Cockpit Ovirt
cockpit-ovirt
Mom
mom
Log Collector
log_collector

CVEs (34)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Ovirt
Redhat
2Enterprise Virtualization Manager
Ovirt
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in c...Show more
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.Show less
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt Ansible Roles
Nov 21, 2024
Jun 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provis...Show more
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.Show less
2Ovirt
Redhat
3Ovirt Engine
VirtualizationVirtualization Host
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
1Ovirt
1Ovirt
Nov 21, 2024
Jun 12, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database,...Show more
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.Show less
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt
Nov 21, 2024
Apr 26, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.Show less
1Ovirt
1Ovirt Hosted Engine Setup
Nov 21, 2024
Jan 24, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
2Ovirt
Redhat
2Ovirt
Ovirt Engine
May 13, 2026
Oct 16, 2017
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by re...Show more
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.Show less
1Ovirt
1Ovirt Node
May 13, 2026
Sep 26, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote a...Show more
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.Show less
1Ovirt
1Ovirt
May 13, 2026
Apr 20, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.
1Ovirt
1Ovirt
May 6, 2026
Feb 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this co...Show more
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Ovirt
1Ovirt
May 6, 2026
Sep 8, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.
2Ovirt
Redhat
2Ovirt
Ovirt Engine
May 6, 2026
Sep 8, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
1Ovirt
1Sanlock
Apr 29, 2026
Dec 20, 2012
N/A· v4
N/A· v3
3.6 LOW· v2
The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard file...Show more
The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.Show less
2Ovirt
Ovirt Engine Sdk
33.1.0.5
OvirtOvirt Engine Cli
Apr 29, 2026
Aug 31, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows remote attackers to spoof a server via a man-in-the-middle (MITM) attack.