CVE-2019-3879
published 2019-03-25CVE-2019-3879: It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation…
PriorityP345high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
1.83%
76.5th percentile
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | ovirt | < 4.3.2.1 | 4.3.2.1 |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks
vendor_redhat·2019-03-25·CVSS 8.1
CVE-2019-3879 [HIGH] CWE-862 ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks
ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.
It was discovered that in the ovirt REST API, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (e.g. Basic Operations) could exploit this flaw to delete disks attached to guests.
GHSA
GHSA-9fjf-3vjh-p57c: It was discovered that in the ovirt's REST API before version 4
ghsa_unreviewed·2022-05-13
CVE-2019-3879 [HIGH] CWE-862 GHSA-9fjf-3vjh-p57c: It was discovered that in the ovirt's REST API before version 4
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3879 ovirt-engine: (downstream clone - 4.2.8) ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks [rhev-m-4.2.z]
bugzilla·2019-03-25·CVSS 8.1
CVE-2019-3879 [HIGH] CVE-2019-3879 ovirt-engine: (downstream clone - 4.2.8) ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks [rhev-m-4.2.z]
CVE-2019-3879 ovirt-engine: (downstream clone - 4.2.8) ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks [rhev-m-4.2.z]
+++ This bug is a downstream clone. The original bug is: +++
+++ bug 1642872 +++
Description of problem:
It looks like a new role provides more permissions than it is expected. A new role having: "Reboot VM, Stop VM, Shut Down VM, Hibernate VM, Run VM, Change CD, Remote Log in" is able to delete a VM or its disk.
Version-Release number of selected component (if applicable):
4.2.6
How reproducible:
always
Steps to Reproduce:
1. create a new role, check everything from VM/Basic Operations
2. assing a new user with the new role
3. delete any V you wish
Actual results:
VM is deleted
Expected results:
it is not allowed
Bugzilla
CVE-2019-3879 ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks
bugzilla·2019-03-04·CVSS 8.1
CVE-2019-3879 [HIGH] CVE-2019-3879 ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks
CVE-2019-3879 ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks
It was discovered that in the ovirt REST API, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.
Discussion:
Upstream fix:
https://gerrit.ovirt.org/#/c/98153/
---
(In reply to Doran Moppert from comment #2)
> Upstream fix:
>
> https://gerrit.ovirt.org/#/c/98153/
$ git tag --contains b6840a6c6221470c31e5f4d9f718239a9d44149d
ovirt-engine-4.3.2.1
ovirt-engine-4.3.3
ovirt-engine-4.3.3.1
ovirt-engine-4.3.3.2
ovirt-engine-4.3.3.3
ovirt-engine-4.3.3.4
ovirt-engine-4.3.3.
Bugzilla
CVE-2019-3879 ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks [rhev-m-4.3.0]
bugzilla·2018-10-25·CVSS 8.1
CVE-2019-3879 [HIGH] CVE-2019-3879 ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks [rhev-m-4.3.0]
CVE-2019-3879 ovirt-engine: Missing permissions check in web ui allows a user with basic privileges to delete disks [rhev-m-4.3.0]
Description of problem:
It looks like a new role provides more permissions than it is expected. A new role having: "Reboot VM, Stop VM, Shut Down VM, Hibernate VM, Run VM, Change CD, Remote Log in" is able to delete a VM or its disk.
Version-Release number of selected component (if applicable):
4.2.6
How reproducible:
always
Steps to Reproduce:
1. create a new role, check everything from VM/Basic Operations
2. assing a new user with the new role
3. delete any V you wish
Actual results:
VM is deleted
Expected results:
it is not allowed
Discussion:
I cannot reproduce this. What were the exact steps to reproduce?
I tried these steps:
1. Create a custom ro
2019-03-25
Published