PT-2014-3505 · Ovirt · Ovirt
CVE-2014-0153
·
Publicado
2014-09-08
·
Atualizado
2023-02-13
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
oVirt versions 3.4.0 and earlier
Description
The issue concerns the REST API in oVirt, where session IDs are stored in HTML5 local storage. This allows remote attackers to obtain sensitive information via a crafted web page.
Recommendations
For versions 3.4.0 and earlier, consider disabling the use of HTML5 local storage for session IDs until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ovirt