First published: Thu Jun 06 2019(Updated: )
cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cfme-gemset | >=5.9.0.22<=5.9.9.3 | |
Redhat Cfme-gemset | >=5.10.0.33<=5.10.4.3 | |
Redhat Cloudforms | =4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10159 is a vulnerability in cfme-gemset versions 5.10.4.3 and below and 5.9.9.3 and below that allows an attacker with access to an unprivileged user to access all VM migration logs.
CVE-2019-10159 has a severity rating of 4.3 (medium).
An attacker can exploit CVE-2019-10159 by leveraging an improperly authorized migration log controller to access all VM migration logs.
cfme-gemset versions 5.10.4.3 and below and 5.9.9.3 and below are affected by CVE-2019-10159.
Yes, a fix for CVE-2019-10159 is available. It is recommended to update to a version that is not vulnerable.