REDHAT-BUG-988774: XSS
A cross-site scripting (XSS) flaw was found in the RedirectServlet of the oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M). A remote attacker could provide a specially-crafted link, that when visited by an unsuspecting RHEV-M / oVirt user would lead to arbitrary script execution in the context of the RHEV-M / oVirt domain. Access to the RedirectServlet does not require authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-988774?
REDHAT-BUG-988774 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix REDHAT-BUG-988774?
To fix REDHAT-BUG-988774, users should update to the latest patched version of the Red Hat oVirt Engine or Red Hat Enterprise Virtualization Manager.
What are the potential impacts of REDHAT-BUG-988774?
The potential impacts of REDHAT-BUG-988774 include unauthorized script execution which could compromise user data or session integrity.
Who is affected by REDHAT-BUG-988774?
REDHAT-BUG-988774 affects users of the Red Hat oVirt Engine and Red Hat Enterprise Virtualization Manager.
Is there a workaround for REDHAT-BUG-988774?
Currently, there are no recommended workarounds for REDHAT-BUG-988774 other than applying the available security updates.