TROYANOSYVIRUS
Back to CVEs

CVE-2024-7259

MEDIUM
4.9

Description

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.

CVE Details

CVSS v3.1 Score4.9
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published9/26/2024
Last Modified1/8/2026
Sourcenvd
Honeypot Sightings0

Affected Products

ovirt:ovirt-engineredhat:virtualization

Weaknesses (CWE)

CWE-312

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.