CVE-2014-0151: Red Hat Ovirt-Engine
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
Affected products
- Red Hat Ovirt-Engine: up to and including 3.5.0
Published 2015-02-13. Last modified 2026-06-17.