CVE Tools

Ovirt

13 CVEs tracked since 2012. Since Dec 2012, none of them reached CISA KEV.

Ovirt CVEs per month

Dec 2012 to Aug 2020. Point at a month, or focus the strip and use the arrow keys.
Ovirt CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2012-1210
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-0920
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-0210
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-0640
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-1130
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-0820

Products

The products that kept showing up in Ovirt's monthly top three, with their CVEs summed over those months.

  1. Ovirt75 months
  2. Ovirt-engine33 months
  3. Ovirt-ansible-roles11 month
  4. Sanlock11 month
  5. Vdsm11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Ovirt.

  1. CVE-2024-7259Ovirt-engine: potential exposure of cleartext provider passwords via web ui4.9
  2. CVE-2024-0822Ovirt: authentication bypass7.5
  3. CVE-2022-3193An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigge...6.1
  4. CVE-2022-2806It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev5.5
  5. CVE-2022-0207A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.4.7
  6. CVE-2022-0435A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the ...8.8
  7. CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thu...7.8
  8. CVE-2020-35497A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.6.5
  9. CVE-2020-10775An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the t...5.3
  10. CVE-2020-14333A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting in a reflected cross-site scripting attack. Thi...6.3
  11. CVE-2019-19336A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This f...6.1
  12. CVE-2013-0293oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation7.8
  13. CVE-2012-4480mom creates world-writable pid files in /var/run7.8
  14. CVE-2012-5518vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)7.5
  15. CVE-2015-1780oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center6.5

The record

Peak rank
#93 in Sep 2014
Busiest month shown
Jun 2018, 4 CVEs
Months with a KEV entry
0 since Dec 2012
Monthly snapshots
6 since 2012
Ovirt's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store