Data Leak Vulnerability in CFME Gemset by Red Hat
CVE-2019-10159

4.3MEDIUM

Key Information:

Vendor
Red Hat
Status
Vendor
CVE Published:
14 June 2019

Summary

CFME Gemset versions up to 5.10.4.3 and 5.9.9.3 may be susceptible to data exposure due to insufficient authorization in the migration log controller. This allows unprivileged users with access to the system to retrieve sensitive VM migration logs, potentially compromising the security of virtual machine data. Organizations using these versions should implement necessary patches to ensure data integrity and confidentiality.

Affected Version(s)

cfme 5.10.4.3 and below, 5.9.9.3 and below

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.