CVE-2014-0152: Medium severity ovirt vulnerability
Published Sep 8, 2014
·Updated
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
Affected Software
10 affected components
Ovirt oVirt<=3.4.0
redhat Ovirt-engine=3.0.0
redhat Ovirt-engine=3.1.0
redhat Ovirt-engine=3.2.0
redhat Ovirt-engine=3.3.0
redhat Ovirt-engine=3.3.2-rc1
redhat Ovirt-engine=3.3.3
redhat Ovirt-engine=3.3.4
redhat Ovirt-engine=3.3.5
redhat Ovirt-engine=3.4.0-rc1
Remediation
Patch Available
Patch Available
Event History
Sep 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0152?
CVE-2014-0152 has a medium severity level due to its session fixation vulnerability in the web admin interface.
2
How do I fix CVE-2014-0152?
To fix CVE-2014-0152, upgrade to oVirt version 3.4.1 or later, which addresses the vulnerability.
3
What versions are affected by CVE-2014-0152?
CVE-2014-0152 affects oVirt versions 3.4.0 and earlier, as well as Red Hat oVirt Engine versions 3.0.0 to 3.4.0-rc1.
4
What type of attack does CVE-2014-0152 facilitate?
CVE-2014-0152 facilitates session hijacking attacks, allowing remote attackers to take over web sessions.
5
Is there a workaround for CVE-2014-0152 if I cannot upgrade?
A potential workaround for CVE-2014-0152 includes implementing additional session management controls to mitigate the risks.