A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.
2020-12-21T17:15:12.757
2024-11-21T05:27:25.683
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ovirt | ovirt-engine | ≤ 4.4.3 | Yes |
Application | redhat | virtualization | 4.0 | Yes |