Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19336

Опубликовано: 19 мар. 2020
Источник: nvd
CVSS3: 5.4
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ovirt:ovirt-engine:*:*:*:*:*:*:*:*
Версия до 4.3.8 (исключая)
Конфигурация 2
cpe:2.3:a:redhat:virtualization:4.3:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00307
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
около 6 лет назад

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

github
больше 3 лет назад

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

EPSS

Процентиль: 53%
0.00307
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79