oVirt Engine CVE-2014-3706 Certificate Validation Security Bypass Vulnerability
BID:101507
Info
oVirt Engine CVE-2014-3706 Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 101507 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3706 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2017 12:00AM |
| Updated: | Oct 18 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Redhat Enterprise Virtualization Manager 3.4 Redhat Enterprise Virtualization Manager 3.3 oVirt oVirt Engine 0 |
| Not Vulnerable: | |
Discussion
oVirt Engine CVE-2014-3706 Certificate Validation Security Bypass Vulnerability
oVirt Engine is prone to an security-bypass vulnerability.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
oVirt Engine is prone to an security-bypass vulnerability.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
Exploit / POC
oVirt Engine CVE-2014-3706 Certificate Validation Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
oVirt Engine CVE-2014-3706 Certificate Validation Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
oVirt Engine CVE-2014-3706 Certificate Validation Security Bypass Vulnerability
References:
References:
- CVE-2014-3706 (Redhat)
- oVirt Homepage (oVirt )
- Bug 1154977 - (CVE-2014-3706) CVE-2014-3706 ovirt-engine: connection does not v (Redhat)