CVE-2014-0153
published 2014-09-08CVE-2014-0153: The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.33%
68.0th percentile
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | ovirt | <= 3.4.0 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ovirt-engine-api: session ID stored in HTML5 local storage
vendor_redhat·2014-03-17·CVSS 4.3
CVE-2014-0153 [MEDIUM] CWE-522 ovirt-engine-api: session ID stored in HTML5 local storage
ovirt-engine-api: session ID stored in HTML5 local storage
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.
GHSA
GHSA-mpx4-8rp2-j882: The REST API in oVirt 3
ghsa_unreviewed·2022-05-13
CVE-2014-0153 [MEDIUM] CWE-200 GHSA-mpx4-8rp2-j882: The REST API in oVirt 3
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0153 ovirt-engine-api: session ID stored in HTML5 local storage
bugzilla·2014-03-28·CVSS 4.3
CVE-2014-0153 [MEDIUM] CVE-2014-0153 ovirt-engine-api: session ID stored in HTML5 local storage
CVE-2014-0153 ovirt-engine-api: session ID stored in HTML5 local storage
It was found that the oVirt web admin interface stored session IDs in HTML5 local storage. A remote attacker could provide a specially crafted web page that, when visited by a user with a valid REST API session, would allow the attacker to read the session ID from local storage. This is possible because HTML5 local storage is not protected by the same-origin policy (SOP).
Discussion:
Upstream bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1077448
Upstream patch commit:
http://gerrit.ovirt.org/#/c/25987/
---
Created ovirt-engine tracking bugs for this issue:
Affects: fedora-all [bug 1081926]
---
Note that the RESTAPI doesn't store the session IDs anywhere, it is the client that does so, in this case the UI
Bugzilla
CVE-2014-0153 ovirt-engine: ovirt-engine-api: session ID stored in HTML5 local storage [fedora-all]
bugzilla·2014-03-28·CVSS 4.3
CVE-2014-0153 [MEDIUM] CVE-2014-0153 ovirt-engine: ovirt-engine-api: session ID stored in HTML5 local storage [fedora-all]
CVE-2014-0153 ovirt-engine: ovirt-engine-api: session ID stored in HTML5 local storage [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pleas
2014-09-08
Published