Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3879

Опубликовано: 25 мар. 2019
Источник: nvd
CVSS3: 6.5
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ovirt:ovirt:*:*:*:*:*:*:*:*
Версия до 4.3.2.1 (исключая)
Конфигурация 2
cpe:2.3:o:redhat:virtualization:4.2:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00573
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 6.5
redhat
почти 7 лет назад

It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.

CVSS3: 8.1
github
больше 3 лет назад

It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.

EPSS

Процентиль: 68%
0.00573
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862
CWE-862