534
VMScore

CVE-2014-7851

Published: 16/10/2017 Updated: 13/02/2023
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

oVirt 3.2.2 up to and including 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

Vulnerable Product Search on Vulmon Subscribe to Product

ovirt ovirt 3.3.2

ovirt ovirt 3.4.0

redhat ovirt-engine 3.2.2

redhat ovirt-engine 3.3

redhat ovirt-engine 3.3.0.1

redhat ovirt-engine 3.3.1

redhat ovirt-engine 3.3.2

redhat ovirt-engine 3.3.3

redhat ovirt-engine 3.3.4

redhat ovirt-engine 3.3.5

redhat ovirt-engine 3.4.0

redhat ovirt-engine 3.4.1

redhat ovirt-engine 3.4.2

redhat ovirt-engine 3.4.3

redhat ovirt-engine 3.4.4

redhat ovirt-engine 3.5.0