CVE-2024-7259

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ovirt:ovirt-engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*

History

30 Jul 2025, 15:46

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-7259 - () https://access.redhat.com/security/cve/CVE-2024-7259 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2314229 - () https://bugzilla.redhat.com/show_bug.cgi?id=2314229 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:ovirt:ovirt-engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
First Time Redhat
Redhat virtualization
Ovirt
Ovirt ovirt-engine

30 Sep 2024, 12:46

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en oVirt. Un usuario con privilegios de administrador, incluidos los usuarios con el permiso ReadOnlyAdmin, puede usar las herramientas para desarrolladores del navegador para ver las contraseñas del proveedor en texto plano.

26 Sep 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 16:15

Updated : 2025-07-30 15:46


NVD link : CVE-2024-7259

Mitre link : CVE-2024-7259

CVE.ORG link : CVE-2024-7259


JSON object : View

Products Affected

redhat

  • virtualization

ovirt

  • ovirt-engine
CWE
CWE-312

Cleartext Storage of Sensitive Information