cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.
References
Link Resource
https://access.redhat.com/errata/RHSA-2019:2466 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10159 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2019-06-14T13:53:19

Updated: 2019-08-13T13:06:06

Reserved: 2019-03-27T00:00:00


Link: CVE-2019-10159

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-06-14T14:29:00.407

Modified: 2023-02-12T23:33:10.837


Link: CVE-2019-10159

JSON object: View

cve-icon Redhat Information

No data.