Ovirt Engine

Vendor:

First CVE: Sep 8, 2014 · Active for 11 years

10
Total CVEs
More Total CVEs than 89% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ovirt Engine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 8, 2014
11 years ago
Most Recent CVE
Aug 24, 2020
2,163 days ago

CVE Severity & Scoring

Ovirt Engine10 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (80.0%)
Unknown2 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (50.0%)
High3 (30.0%)
Unknown2 (20.0%)
User Interaction
None5 (50.0%)
Unknown2 (20.0%)
Required3 (30.0%)
Privileges Required
Low5 (50.0%)
High1 (10.0%)
None2 (20.0%)
Unknown2 (20.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
Mar 25, 20198.828NONO
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
Sep 8, 20146.823NONO
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
Aug 7, 20176.122NONO
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.
Jun 6, 20176.522NONO
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to
Mar 6, 20185.320NONO
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session d
Oct 16, 20177.519NONO
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to
Mar 13, 20184.818NONO
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecifi
Feb 13, 20156.818NONO
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Nov 22, 20196.517NONO
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing at
Aug 24, 20205.316NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Ovirt Engine

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.1.018.81.0%00
3.5.017.51.0%00
3.4.417.51.0%00
3.4.317.51.0%00
3.4.217.51.0%00
3.4.117.51.0%00
3.4.027.41.1%00
3.3.527.21.4%00
3.3.427.31.3%00
3.3.327.31.3%00
3.3.227.21.4%00
3.3.117.51.0%00
3.3.0.117.51.0%00
3.3.016.81.8%00
3.317.51.0%00
3.2.217.51.0%00
3.2.016.81.8%00
3.1.016.81.8%00
3.0.016.81.8%00