CVE-2014-0151: Red Hat Ovirt-Engine

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.

Affected products

  • Red Hat Ovirt-Engine: up to and including 3.5.0

Published 2015-02-13. Last modified 2026-06-17.