Vulnerabilities > Ovirt > Ovirt Engine > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-25 CVE-2024-0822 Improper Authentication vulnerability in Ovirt Ovirt-Engine
An authentication bypass vulnerability was found in overt-engine.
network
low complexity
ovirt CWE-287
7.5
2022-03-10 CVE-2022-0847 Improper Initialization vulnerability in multiple products
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values.
7.8
2019-11-01 CVE-2013-4367 Incorrect Permission Assignment for Critical Resource vulnerability in Ovirt Ovirt-Engine 3.2
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.
local
low complexity
ovirt CWE-732
7.8