Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4h4-7mqm-9j6c

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.

EPSS

Процентиль: 20%
0.00063
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.8
redhat
больше 9 лет назад

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.

CVSS3: 6.8
nvd
почти 9 лет назад

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.

EPSS

Процентиль: 20%
0.00063
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-284