CVE-2014-0153

The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ovirt:ovirt:*:*:*:*:*:*:*:*

History

13 Feb 2023, 00:33

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-0153', 'name': 'https://access.redhat.com/security/cve/CVE-2014-0153', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1081875', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1081875', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0506', 'name': 'https://access.redhat.com/errata/RHSA-2014:0506', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2014-0153 ovirt-engine-api: session ID stored in HTML5 local storage The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.

02 Feb 2023, 15:16

Type Values Removed Values Added
Summary The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page. CVE-2014-0153 ovirt-engine-api: session ID stored in HTML5 local storage
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-0153 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1081875 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0506 -

Information

Published : 2014-09-08 14:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-0153

Mitre link : CVE-2014-0153

CVE.ORG link : CVE-2014-0153


JSON object : View

Products Affected

ovirt

  • ovirt
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor