Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ovirt-engine 信息泄露漏洞
Vulnerability Description
ovirt-engine是一款开源的虚拟化管理引擎。 ovirt-engine 3.4.4及之前版本中存在信息泄露漏洞,该漏洞源于程序没有为会话ID的Set-Cookie头设置HTTPOnly标志。远程攻击者可通过脚本访问cookie利用该漏洞获取潜在的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A