CVE-2015-1841
published 2015-09-08CVE-2015-1841: The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM…
PriorityP410low3.7CVSS 2.0
AVLACHAuNCPIPAP
EPSS
0.33%
24.5th percentile
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization | — | — |
CVSS provenance
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hf5q-rvmp-xhfh: The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in t
ghsa_unreviewed·2022-05-17
CVE-2015-1841 [LOW] GHSA-hf5q-rvmp-xhfh: The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in t
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.
Red Hat
RHEV-M: webadmin automatic logout fails if VM is selected
vendor_redhat·2015-03-26·CVSS 3.7
CVE-2015-1841 [LOW] RHEV-M: webadmin automatic logout fails if VM is selected
RHEV-M: webadmin automatic logout fails if VM is selected
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.
It was found that the idle timeout in the Red Hat Enterprise Virtualization Manager Web Admin interface failed to log out a session if a VM has been selected in the VM grid view. This could allow a local attacker to access the web interface if it was left unattended.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1302 chromium-browser: information leak in PDF viewer
bugzilla·2015-11-11·CVSS 7.5
CVE-2015-1302 [HIGH] CVE-2015-1302 chromium-browser: information leak in PDF viewer
CVE-2015-1302 chromium-browser: information leak in PDF viewer
An unspecified information leak flaw was found in the PDF viewer component of the Chromium browser.
Upstream bug:
https://code.google.com/p/chromium/issues/detail?id=520422
External References:
http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.html
Discussion:
Search using the id of the private upstream bug finds this upstream commit:
https://chromium.googlesource.com/chromium/src/+/a42545fa19dcbdca14c7e53e214b05b3d9356af5
---
The above patch is included in the chromium-browser packages as shipped with Red Hat Enterprise Linux 6 Supplementary as of RHSA-2015:1841 updating packages to version 45.0.2454.101.
https://rhn.redhat.com/errata/RHSA-2015-1841.html
Upstream confirmed this issue was not fi
Bugzilla
CVE-2015-1303 chromium-browser: Cross-origin bypass in DOM
bugzilla·2015-09-25·CVSS 7.5
CVE-2015-1303 [HIGH] CVE-2015-1303 chromium-browser: Cross-origin bypass in DOM
CVE-2015-1303 chromium-browser: Cross-origin bypass in DOM
An unspecified cross-origin bypass flaw was found in the DOM component of the Chrome / Chromium browser.
Upstream bug:
https://code.google.com/p/chromium/issues/detail?id=530301
External References:
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_24.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1841 https://rhn.redhat.com/errata/RHSA-2015-1841.html
Bugzilla
CVE-2015-1304 chromium-browser: Cross-origin bypass in V8
bugzilla·2015-09-25·CVSS 7.5
CVE-2015-1304 [HIGH] CVE-2015-1304 chromium-browser: Cross-origin bypass in V8
CVE-2015-1304 chromium-browser: Cross-origin bypass in V8
An unspecified cross-origin bypass flaw was found in the V8 component of the Chrome / Chromium browser.
Upstream bug:
https://code.google.com/p/chromium/issues/detail?id=531891
External References:
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_24.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1841 https://rhn.redhat.com/errata/RHSA-2015-1841.html
Bugzilla
CVE-2015-1841 RHEV-M: webadmin automatic logout fails if VM is selected
bugzilla·2015-03-26·CVSS 3.7
CVE-2015-1841 [LOW] CVE-2015-1841 RHEV-M: webadmin automatic logout fails if VM is selected
CVE-2015-1841 RHEV-M: webadmin automatic logout fails if VM is selected
Einav Cohen of Red Hat reports:
When browsing to the web-admin, selecting the VMs main tab, selecting a VM in
the VMs grid and leaving the web-admin idle, the web-admin doesn't log out.
Discussion:
Acknowledgement:
This issue was discovered by Einav Cohen or Red Hat.
---
This issue has been addressed in the following products:
RHEV-H and Agents for RHEL-6
RHEV-H and Agents for RHEL-7
Via RHSA-2015:1713 https://rhn.redhat.com/errata/RHSA-2015-1713.html
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2015-1841
2015-09-08
Published