PT-2014-3505 · Ovirt · Ovirt

Published

2014-09-08

·

Updated

2023-02-13

·

CVE-2014-0153

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions oVirt versions 3.4.0 and earlier
Description The issue concerns the REST API in oVirt, where session IDs are stored in HTML5 local storage. This allows remote attackers to obtain sensitive information via a crafted web page.
Recommendations For versions 3.4.0 and earlier, consider disabling the use of HTML5 local storage for session IDs until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2014-0153
RHSA-2014:0506

Affected Products

Ovirt