A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2020-03-19T13:11:16

Updated: 2024-08-05T02:16:47.108Z

Reserved: 2019-11-27T00:00:00

Link: CVE-2019-19336

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-03-19T14:15:11.643

Modified: 2020-03-23T16:44:10.957

Link: CVE-2019-19336

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-01-11T00:00:00Z

Links: CVE-2019-19336 - Bugzilla