Data Leak Vulnerability in CFME Gemset by Red Hat
CVE-2019-10159
4.3MEDIUM
Summary
CFME Gemset versions up to 5.10.4.3 and 5.9.9.3 may be susceptible to data exposure due to insufficient authorization in the migration log controller. This allows unprivileged users with access to the system to retrieve sensitive VM migration logs, potentially compromising the security of virtual machine data. Organizations using these versions should implement necessary patches to ensure data integrity and confidentiality.
Affected Version(s)
cfme 5.10.4.3 and below, 5.9.9.3 and below
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved