CVE-2024-7259

MEDIUM

Ovirt-engine < 4.5.7 - Cleartext Storage

Title source: rule
STIX 2.1

Description

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.

Scores

CVSS v3 4.9
EPSS 0.0015
EPSS Percentile 34.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
ovirt/ovirt-engine < 4.5.7
Published Sep 26, 2024
Tracked Since Feb 18, 2026