PT-2019-11603 · Red Hat · Cfme-Gemset

Published

2019-06-14

·

Updated

2023-02-12

·

CVE-2019-10159

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: cfme-gemset versions 5.10.4.3 and below cfme-gemset versions 5.9.9.3 and below
Description: The issue is related to an improper authorization in the migration log controller, which can lead to a data leak. An attacker with access to an unprivileged user account can access all available VM migration logs.
Recommendations: For versions 5.10.4.3 and below, update to a version above 5.10.4.3 to resolve the issue. For versions 5.9.9.3 and below, update to a version above 5.9.9.3 to resolve the issue.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2019-10159
RHSA-2019:2466

Affected Products

Cfme-Gemset