← Vulnerability feed

Vulnerability record · CVE-2018-1062 · published 6 March 2018

CVE-2018-1062: Redhat ovirt-engine vulnerability

Redhat · Ovirt Engine

A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later allocated to a new disk attached to another VM, potentially sensitive data could be revealed to privileged users of that VM.

5.3 CVSS 3.1 Medium EPSS 1.4% · top 29.4% CWE-212 · CWE-212
5.3CVSS 3.1 base score, v2 3.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later allocated to a new disk attached to another VM, potentially sensitive data could be revealed to privileged users of that VM.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1062 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-7510Redhat ovirt-engine information exposure vulnerabilityIn ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.EPSS 1.0%7.5CVE-2014-7851Ovirt permissions and access controls vulnerabilityoVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowle…EPSS 1.0%6.8CVE-2014-0151Redhat ovirt-engine cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for …EPSS 0.64%6.8CVE-2014-0152Ovirt vulnerabilitySession fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified v…EPSS 1.8%6.5CVE-2015-1780Redhat ovirt-engine incorrect authorization vulnerabilityoVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-centerEPSS 1.0%6.5CVE-2016-3077Redhat ovirt-engine memory buffer overflow vulnerabilityThe VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for a…EPSS 1.00%6.1CVE-2016-3113Redhat ovirt-engine cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.EPSS 2.7%5.3CVE-2020-10775Oracle virtualization open redirect vulnerabilityAn Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary we…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2018-1062), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.