vulnerability

Oracle Linux: CVE-2024-7259: ELSA-2024-12701: ovirt-engine security update (MODERATE)

Severity
6
CVSS
(AV:N/AC:M/Au:M/C:C/I:N/A:N)
Published
Sep 26, 2024
Added
Jun 30, 2025
Modified
Dec 3, 2025

Description

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.

Solutions

oracle-linux-upgrade-ovirt-engineoracle-linux-upgrade-ovirt-engine-backendoracle-linux-upgrade-ovirt-engine-dbscriptsoracle-linux-upgrade-ovirt-engine-health-check-bundleroracle-linux-upgrade-ovirt-engine-restapioracle-linux-upgrade-ovirt-engine-setuporacle-linux-upgrade-ovirt-engine-setup-baseoracle-linux-upgrade-ovirt-engine-setup-plugin-cinderliboracle-linux-upgrade-ovirt-engine-setup-plugin-imageiooracle-linux-upgrade-ovirt-engine-setup-plugin-ovirt-engineoracle-linux-upgrade-ovirt-engine-setup-plugin-ovirt-engine-commonoracle-linux-upgrade-ovirt-engine-setup-plugin-vmconsole-proxy-helperoracle-linux-upgrade-ovirt-engine-setup-plugin-websocket-proxyoracle-linux-upgrade-ovirt-engine-toolsoracle-linux-upgrade-ovirt-engine-tools-backuporacle-linux-upgrade-ovirt-engine-vmconsole-proxy-helperoracle-linux-upgrade-ovirt-engine-webadmin-portaloracle-linux-upgrade-ovirt-engine-websocket-proxyoracle-linux-upgrade-python3-ovirt-engine-lib
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.