Vulnerability Description
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ovirt-Engine | >= 4.2.0, <= 4.2.2 |
Related Weaknesses (CWE)
References
- https://gerrit.ovirt.org/#/c/87265/2/frontend/webadmin/modules/webadmin/src/mainPatch
- https://gerrit.ovirt.org/c/87265/Issue Tracking
- https://gerrit.ovirt.org/#/c/87265/2/frontend/webadmin/modules/webadmin/src/mainPatch
- https://gerrit.ovirt.org/c/87265/Issue Tracking
FAQ
What is CVE-2018-1000095?
CVE-2018-1000095 is a vulnerability with a CVSS score of 4.8 (MEDIUM). oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in v...
How severe is CVE-2018-1000095?
CVE-2018-1000095 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000095?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ovirt-Engine.