A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root.
2019-03-25T18:29:00.933
2024-11-21T04:42:38.220
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ovirt | vdsm | ≤ 4.30.3 | Yes |
Application | ovirt | vdsm | ≤ 4.30.8 | Yes |
Application | redhat | gluster_storage | 3.0 | Yes |