CVE-2024-7259

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Sep 30, 2024
CWE ID 312

Summary

CVE-2024-7259 is a vulnerability affecting oVirt, an open-source virtualization management engine. This issue grants users with administrator privileges, including those with the ReadOnlyAdmin permission, the ability to access Provider passwords in cleartext using browser developer tools. This poses a significant risk as unauthorized users could potentially gain access to sensitive information, leading to potential data breaches or unauthorized system access. It is essential that users apply the recommended patches to mitigate this vulnerability and secure their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Virtualization

Affected Vendors

  • Red Hat