CVE-2014-0154
published 2015-02-13CVE-2014-0154: oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain…
PriorityP420medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.74%
75.2th percentile
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | ovirt | <= 3.4.4 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mxr-r8gm-qxvv: oVirt Engine before 3
ghsa_unreviewed·2022-05-17
CVE-2014-0154 [MEDIUM] CWE-200 GHSA-3mxr-r8gm-qxvv: oVirt Engine before 3
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Red Hat
ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
vendor_redhat·2014-03-17·CVSS 5.0
CVE-2014-0154 [MEDIUM] CWE-522 ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
It was found that the oVirt web admin interface did not include the HttpOnly flag when setting session IDs with the Set-Cookie header. This flaw could make it is easier for a remote attacker to hijack an oVirt web admin session by leveraging a cross-site scripting (XSS) vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0154 ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
bugzilla·2014-03-28·CVSS 5.0
CVE-2014-0154 [MEDIUM] CVE-2014-0154 ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
CVE-2014-0154 ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
It was found that the oVirt web admin interface did not include the HttpOnly flag when setting session IDs with the Set-Cookie header. As a result, it is easier for remote attackers to hijack an oVirt web admin session by leveraging a cross-site scripting (XSS) vulnerability.
Discussion:
Upstream bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1077450
Upstream patch commit:
http://gerrit.ovirt.org/#/c/25915/
---
Created ovirt-engine tracking bugs for this issue:
Affects: fedora-all [bug 1081929]
---
This issue has been addressed in the following products:
RHEV Manager version 3.5
Via RHSA-2015:0158 https://rhn.redhat.com/errata/RHSA-2015-0158.html
Bugzilla
CVE-2014-0154 ovirt-engine: ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set [fedora-all]
bugzilla·2014-03-28·CVSS 5.0
CVE-2014-0154 [MEDIUM] CVE-2014-0154 ovirt-engine: ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set [fedora-all]
CVE-2014-0154 ovirt-engine: ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field w
2015-02-13
Published