A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.
2024-09-26T16:15:08.997
2025-07-30T15:46:46.760
Analyzed
CVSSv3.1: 4.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ovirt | ovirt-engine | < 4.5.7 | Yes |
Application | redhat | virtualization | 4.0 | No |