Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-353g-73mj-6wf9

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

EPSS

Процентиль: 59%
0.00388
Низкий

7.5 High

CVSS3

Связанные уязвимости

redhat
почти 11 лет назад

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

CVSS3: 7.5
nvd
больше 8 лет назад

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

EPSS

Процентиль: 59%
0.00388
Низкий

7.5 High

CVSS3