First published: Mon Jan 15 2024(Updated: )
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
oVirt Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0822 has been classified as a critical vulnerability due to its potential impact on authentication mechanisms.
To mitigate CVE-2024-0822, apply the latest patches provided by the oVirt project that address the authentication bypass issue.
CVE-2024-0822 allows unauthorized users to create accounts in the system, compromising the integrity of user management.
CVE-2024-0822 affects all versions of oVirt Engine prior to the security update that resolves the vulnerability.
CVE-2024-0822 was identified during an internal penetration testing assessment, highlighting flaws in the CreateUserSession command.