Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ovirt-Engine | <= 3.5.0 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2015-0158.html
- http://www.ovirt.org/OVirt_3.5_Release_NotesVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1077441
- http://rhn.redhat.com/errata/RHSA-2015-0158.html
- http://www.ovirt.org/OVirt_3.5_Release_NotesVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1077441
FAQ
What is CVE-2014-0151?
CVE-2014-0151 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a RES...
How severe is CVE-2014-0151?
CVE-2014-0151 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0151?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ovirt-Engine.