Back

HIGH

Ovirt: authentication bypass

Published Jan 25, 2024

Description

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 25, 2024
Updated Nov 20, 2025
Reserved Jan 23, 2024
CISA Vulnrichment
Updated Sep 12, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 15, 2024
ENISA EUVD
Assigner redhat
Published Jan 25, 2024
Updated Nov 20, 2025
Exploited since n/a
EUVD-2024-16606