The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows remote attackers to spoof a server via a man-in-the-middle (MITM) attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ovirt | ovirt | 3.1 |
| ovirt | ovirt-engine-cli | * |
| ovirt-engine-sdk | 3.1.0.5 | * |
The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ovirt | sanlock | - |
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | ovirt-engine | 3.3.5 |
| redhat | ovirt-engine | 3.2.0 |
| redhat | ovirt-engine | 3.3.4 |
| redhat | ovirt-engine | 3.3.3 |
| redhat | ovirt-engine | 3.3.0 |
| redhat | ovirt-engine | 3.1.0 |
| ovirt | ovirt | * |
| redhat | ovirt-engine | 3.3.2 |
| redhat | ovirt-engine | 3.4.0 |
| redhat | ovirt-engine | 3.0.0 |
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ovirt | ovirt | * |
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ovirt | ovirt | * |