<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – oVirt (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ovirt.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ovirt-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – oVirt (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:07 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2013-0293 – oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0293</guid>
    <pubDate>Tue, 10 Dec 2019 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0293</strong></p>
  <p>oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4367 – ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files wor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4367</guid>
    <pubDate>Fri, 01 Nov 2019 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4367</strong></p>
  <p>ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10139 – During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible varia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10139</guid>
    <pubDate>Fri, 17 May 2019 16:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10139</strong></p>
  <p>During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3879 – It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3879</guid>
    <pubDate>Mon, 25 Mar 2019 19:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3879</strong></p>
  <p>It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7510 – In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root passwor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7510</guid>
    <pubDate>Mon, 25 Mar 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7510</strong></p>
  <p>In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15113 – ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15113</guid>
    <pubDate>Fri, 27 Jul 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15113</strong></p>
  <p>ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1074 – ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1074</guid>
    <pubDate>Thu, 26 Apr 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1074</strong></p>
  <p>ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1097 – A flaw was found in foreman before 1.16.1. The issue allows users with limited p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1097</guid>
    <pubDate>Wed, 04 Apr 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1097</strong></p>
  <p>A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000018 – An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000018</guid>
    <pubDate>Wed, 24 Jan 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000018</strong></p>
  <p>An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-7851 – oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-7851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-7851</guid>
    <pubDate>Mon, 16 Oct 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-7851</strong></p>
  <p>oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-7851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8170 – ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8170</guid>
    <pubDate>Tue, 26 Sep 2017 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8170</strong></p>
  <p>ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5411 – /var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Inst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5411</guid>
    <pubDate>Tue, 13 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5411</strong></p>
  <p>/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5411">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
