CVE-2024-0822

Source
https://cve.org/CVERecord?id=CVE-2024-0822
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0822.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-0822
Downstream
Published
2024-01-25T15:18:20.439Z
Modified
2026-08-12T03:51:29.103161842Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Ovirt: authentication bypass
Details

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.

Database specific
{
    "cwe_ids": [
        "CWE-1390"
    ],
    "cna_assigner": "redhat",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0822.json"
}
References

Affected packages

Git / github.com/ovirt/ovirt-engine

Affected ranges

Type
GIT
Repo
https://github.com/ovirt/ovirt-engine
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "4.5.0"
        },
        {
            "fixed": "4.5.6"
        }
    ]
}

Affected versions

ovirt-engine-4.*
ovirt-engine-4.5.0
ovirt-engine-4.5.0.1
ovirt-engine-4.5.0.2
ovirt-engine-4.5.1
ovirt-engine-4.5.1.1
ovirt-engine-4.5.1.2
ovirt-engine-4.5.2
ovirt-engine-4.5.2.1
ovirt-engine-4.5.2.2
ovirt-engine-4.5.3.1
ovirt-engine-4.5.4
ovirt-engine-4.5.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0822.json"