CVE-2014-0152: Ovirt
Medium severity, CVSS 6.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
Affected products
- Ovirt Ovirt: up to and including 3.4.0
- Red Hat Ovirt-Engine: version 3.0.0 only; version 3.1.0 only; version 3.2.0 only; version 3.3.0 only; version 3.3.2 only; version 3.3.3 only; …
Published 2014-09-08. Last modified 2026-06-17.