Description
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
References (2)
Core 2
Core References
Patch x_refsource_confirm
http://gerrit.ovirt.org/#/c/25959/
Patch, Vendor Advisory x_refsource_confirm
http://www.ovirt.org/Security_advisories
Scores
EPSS
0.0176
EPSS Percentile
75.6%
Details
Status
published
Products (10)
ovirt/ovirt
< 3.4.0
redhat/ovirt-engine
3.0.0
redhat/ovirt-engine
3.1.0
redhat/ovirt-engine
3.2.0
redhat/ovirt-engine
3.3.0
redhat/ovirt-engine
3.3.2 rc1
redhat/ovirt-engine
3.3.3
redhat/ovirt-engine
3.3.4
redhat/ovirt-engine
3.3.5
redhat/ovirt-engine
3.4.0 rc1
Published
Sep 08, 2014
Tracked Since
Feb 18, 2026