Vulnerabilities > CVE-2019-3879 - Missing Authorization vulnerability in multiple products

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
ovirt
redhat
CWE-862

Summary

It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.

Vulnerable Configurations

Part Description Count
Application
Ovirt
324
OS
Redhat
1

Common Weakness Enumeration (CWE)

Redhat

advisories
rhsa
idRHBA-2019:0802
rpms
  • ovirt-engine-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-backend-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-dbscripts-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-extensions-api-impl-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-extensions-api-impl-javadoc-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-health-check-bundler-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-lib-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-restapi-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-setup-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-setup-base-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-setup-plugin-ovirt-engine-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-setup-plugin-ovirt-engine-common-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-setup-plugin-vmconsole-proxy-helper-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-setup-plugin-websocket-proxy-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-tools-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-tools-backup-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-vmconsole-proxy-helper-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-webadmin-portal-0:4.2.8.7-0.1.el7ev
  • ovirt-engine-websocket-proxy-0:4.2.8.7-0.1.el7ev
  • rhvm-0:4.2.8.7-0.1.el7ev