CVE-2014-7851
HIGHoVirt 3.2.2-3.5.0 - Authenticated Privilege Escalation via Session Token Reuse
Title source: llmDescription
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.
References (2)
Core 2
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1161730
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1165311
Scores
CVSS v3
7.5
EPSS
0.0100
EPSS Percentile
59.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (16)
ovirt/ovirt
3.3.2
ovirt/ovirt
3.4.0
redhat/ovirt-engine
3.2.2
redhat/ovirt-engine
3.3 beta1 (3 CPE variants)
redhat/ovirt-engine
3.3.0.1
redhat/ovirt-engine
3.3.1 (3 CPE variants)
redhat/ovirt-engine
3.3.2 beta1
redhat/ovirt-engine
3.3.3 beta1 (2 CPE variants)
redhat/ovirt-engine
3.3.4 beta1 (2 CPE variants)
redhat/ovirt-engine
3.3.5 rc1
... and 6 more
Published
Oct 16, 2017
Tracked Since
Feb 18, 2026