CVE-2014-0153: Infoleak
Published Sep 8, 2014
·Updated
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.
Affected Software
1 affected component
Ovirt oVirt<=3.4.0
Remediation
Patch Available
Patch Available
Event History
Sep 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0153?
CVE-2014-0153 is considered a medium severity vulnerability due to the potential exposure of sensitive session information.
2
How can CVE-2014-0153 be mitigated?
To mitigate CVE-2014-0153, it is recommended to upgrade to a version of oVirt later than 3.4.0 that does not store session IDs in local storage.
3
What systems are affected by CVE-2014-0153?
CVE-2014-0153 affects oVirt version 3.4.0 and earlier.
4
Can CVE-2014-0153 be exploited remotely?
Yes, CVE-2014-0153 can be exploited remotely by attackers through a crafted web page to obtain sensitive session information.
5
What impact does CVE-2014-0153 have on user privacy?
CVE-2014-0153 can lead to unauthorized access to user session data, compromising user privacy and security.