PT-2019-5286 · Ovirt · Vdsm

Published

2019-02-14

·

Updated

2020-10-19

·

CVE-2019-3831

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vdsm versions 4.19 through 4.30.3 vdsm versions 4.30.5 through 4.30.8
Description The issue is related to the systemd run function in the vdsm server of the Ovirt virtual infrastructure management tool, which fails to properly clean up data at the management level. This could allow a remote attacker to execute arbitrary code.
Recommendations For vdsm versions 4.19 through 4.30.3, update to a version outside of this range to resolve the issue. For vdsm versions 4.30.5 through 4.30.8, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the systemd run function to minimize the risk of exploitation.

Fix

Incorrect Authorization

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02202
CVE-2019-3831
RHSA-2019:0457
RHSA-2019:0458

Affected Products

Vdsm