Red Hat Ovirt-Engine vulnerabilities
2 known vulnerabilities affecting red_hat/ovirt-engine.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-19336MEDIUMCVSS 6.1v4.3.82020-03-19
CVE-2019-19336 [MEDIUM] CWE-79 CVE-2019-19336: A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.
cvelistv5nvd
CVE-2017-15113MEDIUMCVSS 6.6v4.1.7.62018-07-27
CVE-2017-15113 [MEDIUM] CWE-212 CVE-2017-15113: ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file w
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.
cvelistv5nvd