oVirt is a virtualization management platform deployed primarily in enterprise data centers, with vulnerability exposure spanning its core engine, hypervisor node, and host agent components. The vendor's vulnerability profile reflects the structural challenges of managing complex distributed infrastructure: a moderate share of disclosures reach serious severity, and the recurring weakness classes concentrate on sensitive-data exposure, credential handling, input validation in web interfaces, and privilege-management boundaries that are characteristic of large management platforms with broad system-level access. Defenders should treat oVirt deployments as high-value targets and prioritize patches affecting the engine and authentication layers, since these components control cluster-wide operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ovirt over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0847HIGH A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker | Mar 10, 2022 | 7.8 | 98 | YES | YES |
CVE-2022-0435HIGH A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is | Mar 25, 2022 | 8.8 | 67 | NO | NO |
CVE-2018-1072CRITICAL ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the databas | Jun 26, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-1117CRITICAL ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently | Jun 20, 2018 | 9.8 | 29 | NO | NO |
CVE-2019-3879HIGH It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be perfo | Mar 25, 2019 | 8.1 | 26 | NO | NO |
CVE-2013-0293HIGH oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation | Dec 10, 2019 | 7.8 | 25 | NO | NO |
CVE-2012-4480HIGH mom creates world-writable pid files in /var/run | Dec 2, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-10139HIGH During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the ad | May 17, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-1000018HIGH An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file. | Jan 24, 2018 | 7.8 | 24 | NO | NO |
CVE-2012-5518HIGH vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate) | Nov 25, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ovirt.
Media articles that mention a CVE ID that affects a product developed by Ovirt — matched by CVE ID, not by vendor name.