Data Leak Vulnerability in CFME Gemset by Red Hat
CVE-2019-10159
4.3MEDIUM
What is CVE-2019-10159?
CFME Gemset versions up to 5.10.4.3 and 5.9.9.3 may be susceptible to data exposure due to insufficient authorization in the migration log controller. This allows unprivileged users with access to the system to retrieve sensitive VM migration logs, potentially compromising the security of virtual machine data. Organizations using these versions should implement necessary patches to ensure data integrity and confidentiality.
Affected Version(s)
cfme 5.10.4.3 and below, 5.9.9.3 and below