Логотип exploitDog
bind:CVE-2014-7851
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-7851

Количество 3

Количество 3

redhat логотип

CVE-2014-7851

почти 11 лет назад

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2014-7851

больше 8 лет назад

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-353g-73mj-6wf9

больше 3 лет назад

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-7851

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

CVSS2: 4.6
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7851

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
github логотип
GHSA-353g-73mj-6wf9

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу