Bug 1871128
Summary: | CVE-2020-14333 ovirt-engine: Reflected cross site scripting vulnerability | ||
---|---|---|---|
Product: | [oVirt] ovirt-engine | Reporter: | Stoyan Nikolov <snikolov> |
Component: | Frontend.WebAdmin | Assignee: | Artur Socha <asocha> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Ivana Saranova <isaranov> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 4.4.1 | CC: | bugs, dfodor, mperina |
Target Milestone: | ovirt-4.4.3 | Flags: | pm-rhel:
ovirt-4.4+
|
Target Release: | 4.4.3.3 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | ovirt-engine-4.4.3.3 | Doc Type: | No Doc Update |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2020-11-11 06:39:45 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | Infra | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1858184 |
Description
Stoyan Nikolov
2020-08-21 11:49:47 UTC
Steps: 1) Accessing RHEVM auth with script insertions Results: Proper error message is shown. Script is not executed. Verified in: ovirt-engine-4.4.3.5-0.5.el8ev.noarch This bugzilla is included in oVirt 4.4.3 release, published on November 10th 2020. Since the problem described in this bug report should be resolved in oVirt 4.4.3 release, it has been closed with a resolution of CURRENT RELEASE. If the solution does not work for you, please open a new bug report. |