Total vulnerabilities in the database
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
Software | From | Fixed in |
---|---|---|
ovirt / ovirt-engine | - | 4.2.3 |
redhat / virtualization | 4.0 | 4.0.x |
redhat / virtualization_host | 4.0 | 4.0.x |