A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "4.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "4.0"
}
]
}