Description
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.
References (2)
Scores
CVSS v3
8.8
EPSS
0.0083
EPSS Percentile
74.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-134
Status
published
Products (1)
ovirt/ovirt-node
3.0.0-474-gb852fd7
Published
Sep 26, 2017
Tracked Since
Feb 18, 2026