Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6338

Опубликовано: 27 авг. 2016
Источник: redhat
CVSS3: 3.8
CVSS2: 3.7
EPSS Низкий

Описание

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.

It was discovered that the ovirt-engine webadmin session would not properly enforce timeouts. Browser sessions would remain logged in beyond the administratively configured session timeout period.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Virtualization 3ovirt-engineWill not fix
Red Hat Virtualization Engine 4.1org.ovirt.engine-rootFixedRHSA-2017:342712.12.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1369285ovirt-engine: webadmin log out must logout all sessions

EPSS

Процентиль: 42%
0.00519
Низкий

3.8 Low

CVSS3

3.7 Low

CVSS2

Связанные уязвимости

CVSS3: 6.8
nvd
больше 9 лет назад

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.

CVSS3: 6.8
github
больше 4 лет назад

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.

EPSS

Процентиль: 42%
0.00519
Низкий

3.8 Low

CVSS3

3.7 Low

CVSS2