CVE-2013-4181: XSS
A cross-site scripting (XSS) flaw was found in the RedirectServlet of the oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M). A remote attacker could provide a specially-crafted link, that when visited by an unsuspecting RHEV-M / oVirt user would lead to arbitrary script execution in the context of the RHEV-M / oVirt domain. Access to the RedirectServlet does not require authentication.
Other sources
Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M), as used in Red Hat Enterprise Virtualization 3 and 3.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4181?
CVE-2013-4181 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-4181?
To remediate CVE-2013-4181, update to the latest version of Red Hat Enterprise Virtualization that addresses the XSS flaw.
What systems are affected by CVE-2013-4181?
CVE-2013-4181 affects Red Hat Enterprise Virtualization versions 3.0 and 3.2.
What type of vulnerability is CVE-2013-4181?
CVE-2013-4181 is a cross-site scripting (XSS) vulnerability that allows attackers to execute arbitrary scripts.
Can CVE-2013-4181 be exploited remotely?
Yes, CVE-2013-4181 can be exploited remotely via specially crafted links, targeting unsuspecting users.