CVE-2019-10159: Red Hat Cfme-Gemset
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.
Affected products
- Red Hat Cfme-Gemset: from 5.9.0.22, up to and including 5.9.9.3; from 5.10.0.33, up to and including 5.10.4.3
- Red Hat Cloudforms: version 4.7 only
Published 2019-06-14. Last modified 2026-06-17.