CVE-2019-10159: Red Hat Cfme-Gemset

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.

Affected products

  • Red Hat Cfme-Gemset: from 5.9.0.22, up to and including 5.9.9.3; from 5.10.0.33, up to and including 5.10.4.3
  • Red Hat Cloudforms: version 4.7 only

Published 2019-06-14. Last modified 2026-06-17.