CVE-2014-7851

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ovirt:ovirt:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ovirt:ovirt:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3:rc2:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.1:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.1:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.2:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.3:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.3:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.4:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.4:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.3.5:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.0:rc3:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.1:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.2:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.3:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.4.4:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ovirt-engine:3.5.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:18

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=1161730 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=1161730 - Issue Tracking
References () https://bugzilla.redhat.com/show_bug.cgi?id=1165311 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=1165311 - Issue Tracking

Information

Published : 2017-10-16 15:29

Updated : 2024-11-21 02:18


NVD link : CVE-2014-7851

Mitre link : CVE-2014-7851

CVE.ORG link : CVE-2014-7851


JSON object : View

Products Affected

redhat

  • ovirt-engine

ovirt

  • ovirt
CWE
CWE-264

Permissions, Privileges, and Access Controls