CVE-2024-0822
25.01.2024, 16:15
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.Enginsight
Vendor | Product | Version |
---|---|---|
ovirt | ovirt-engine | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1390 - Weak AuthenticationThe product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
References