CVE-2024-7259: Ovirt Ovirt-Engine
Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.
Affected products
- Ovirt Ovirt-Engine: before 4.5.7 (fixed in 4.5.7)
Published 2024-09-26. Last modified 2026-06-17.