Vulnerabilities > Ovirt > Ovirt > 4.2.2.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-25 | CVE-2019-3879 | Missing Authorization vulnerability in multiple products It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. | 8.1 |
2018-06-12 | CVE-2018-1075 | Unspecified vulnerability in Ovirt ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. | 7.8 |