CVE-2018-1000095: XSS
Published Mar 13, 2018
·Updated
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
Affected Software
1 affected component
redhat Ovirt-engine>=4.2.0<=4.2.2
Remediation
Event History
Mar 13, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this oVirt vulnerability?
The vulnerability ID for this oVirt vulnerability is CVE-2018-1000095.
2
What is the severity of CVE-2018-1000095?
The severity of CVE-2018-1000095 is medium with a severity value of 4.8.
3
What is affected by CVE-2018-1000095?
oVirt version 4.2.0 to 4.2.2 is affected by CVE-2018-1000095.
4
How can I fix CVE-2018-1000095?
To fix CVE-2018-1000095, upgrade to version 4.2.3 or later of oVirt.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-1000095?
The Common Weakness Enumeration (CWE) ID for CVE-2018-1000095 is CWE-79.