RHSA-2020:3247HighCVSS 8.1

Red Hat Security Advisory: RHV Manager (ovirt-engine) 4.4 security, bug fix, and enhancement update

Published
August 4, 2020
Last Modified
June 13, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2017-18635 — novnc: XSS vulnerability via the messages propagated to the status field CVE-2019-8331 — bootstrap: XSS in the tooltip or popover data-template attribute CVE-2019-13990 — libquartz: XXE attacks via job description CVE-2019-19336 — ovirt-engine: response_type parameter allows reflected XSS CVE-2020-7598 — nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or proto payload CVE-2020-10775 — ovirt-engine: Redirect to arbitrary URL allows for phishing CVE-2020-11022 — jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods

🔗 References (246)