CVE-2014-0151: CSRF
Published Feb 13, 2015
·Updated
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
Affected Software
1 affected component
redhat Ovirt-engine<=3.5.0
Event History
Feb 13, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0151?
CVE-2014-0151 has a medium severity rating due to its ability to allow remote attackers to hijack user authentication.
2
How do I fix CVE-2014-0151?
To fix CVE-2014-0151, upgrade to oVirt Engine version 3.5.0 or later.
3
Which versions of oVirt Engine are affected by CVE-2014-0151?
CVE-2014-0151 affects oVirt Engine versions before 3.5.0 beta2.
4
What type of vulnerability is CVE-2014-0151?
CVE-2014-0151 is a cross-site request forgery (CSRF) vulnerability.
5
What actions can attackers perform using CVE-2014-0151?
Attackers can exploit CVE-2014-0151 to execute unspecified actions via a REST API request by hijacking user authentication.