PT-2014-3505 · Ovirt · Ovirt

CVE-2014-0153

·

Publicado

2014-09-08

·

Atualizado

2023-02-13

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions oVirt versions 3.4.0 and earlier
Description The issue concerns the REST API in oVirt, where session IDs are stored in HTML5 local storage. This allows remote attackers to obtain sensitive information via a crafted web page.
Recommendations For versions 3.4.0 and earlier, consider disabling the use of HTML5 local storage for session IDs until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0153
RHSA-2014:0506

Produtos afetados

Ovirt