CVE-2018-1000095
published 2018-03-13CVE-2018-1000095: oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This…
PriorityP416medium4.8CVSS 3.0
AVNACLPRHUIRSCCLILAN
EPSS
0.52%
40.5th percentile
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | ovirt-engine | 4.2.0 – 4.2.2 | — |
CVSS provenance
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xqr4-7mxg-hjgj: oVirt version 4
ghsa_unreviewed·2022-05-13
CVE-2018-1000095 [MEDIUM] CWE-79 GHSA-xqr4-7mxg-hjgj: oVirt version 4
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
Red Hat
ovirt-engine: stored XSS in snapshot description and comment
vendor_redhat·2018-03-12·CVSS 4.8
CVE-2018-1000095 [MEDIUM] CWE-79 ovirt-engine: stored XSS in snapshot description and comment
ovirt-engine: stored XSS in snapshot description and comment
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
A stored XSS vulnerability was discovered in ovirt-engine 4.2. Sanitation of HTML elements was not applied correctly to all fields, shows in the management console. An attacker with VM Admin permissions could use this vulnerability to launch XSS attacks against other VM or Cluster administrators.
Package: ovirt-engine (Red Hat Virtualization 4) - Not affected
No detection rules found.
No public exploits indexed.
https://gerrit.ovirt.org/#/c/87265/2/frontend/webadmin/modules/webadmin/src/main/java/org/ovirt/engine/ui/webadmin/widget/host/HostNetworkInterfaceListViewItem.javahttps://gerrit.ovirt.org/c/87265/https://gerrit.ovirt.org/#/c/87265/2/frontend/webadmin/modules/webadmin/src/main/java/org/ovirt/engine/ui/webadmin/widget/host/HostNetworkInterfaceListViewItem.javahttps://gerrit.ovirt.org/c/87265/
2018-03-13
Published