CVE-2015-1780
published 2019-11-22CVE-2015-1780: oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
PriorityP428medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.04%
60.0th percentile
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | ovirt | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3jvc-mp84-rcxx: oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
ghsa_unreviewed·2022-05-24
CVE-2015-1780 [MEDIUM] GHSA-3jvc-mp84-rcxx: oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Red Hat
oVirt: Users with MANIPULATE_STORAGE_DOMAIN can attach a storage domain to any data-center
vendor_redhat·2015-03-05·CVSS 6.5
CVE-2015-1780 [MEDIUM] CWE-285 oVirt: Users with MANIPULATE_STORAGE_DOMAIN can attach a storage domain to any data-center
oVirt: Users with MANIPULATE_STORAGE_DOMAIN can attach a storage domain to any data-center
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Statement: This issue affects the versions of ovirt-engine-backend as shipped with Red Hat Enterprise Virtualization 3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: ovirt-engine-backend (Red Hat Enterprise Virtualization 3) - Will not fix
No detection rules found.
No public exploits indexed.
2019-11-22
Published