PT-2019-5286 · Ovirt · Vdsm

Publicado

2019-02-14

·

Atualizado

2020-10-19

·

CVE-2019-3831

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vdsm versions 4.19 through 4.30.3 vdsm versions 4.30.5 through 4.30.8
Description The issue is related to the systemd run function in the vdsm server of the Ovirt virtual infrastructure management tool, which fails to properly clean up data at the management level. This could allow a remote attacker to execute arbitrary code.
Recommendations For vdsm versions 4.19 through 4.30.3, update to a version outside of this range to resolve the issue. For vdsm versions 4.30.5 through 4.30.8, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the systemd run function to minimize the risk of exploitation.

Correção

Incorrect Authorization

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02202
CVE-2019-3831
RHSA-2019:0457
RHSA-2019:0458

Produtos afetados

Vdsm