← Vulnerability feed

Vulnerability record · CVE-2019-3831 · published 25 March 2019

CVE-2019-3831: Ovirt vdsm incorrect authorization vulnerability

Ovirt · Vdsm

A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root.

6.7 CVSS 3.1 Medium EPSS 1.0% · top 37.6% CWE-863 · Incorrect authorization
6.7CVSS 3.1 base score, v2 9.0
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system user could be abused to execute arbitrary commands as root.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3831 Issue TrackingPatchThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3831 Issue TrackingPatchThird Party Advisory

Track CVE-2019-3831 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed9.8CVE-2017-7481Redhat openshift container platform improper input validation vulnerabilityAnsible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku…EPSS 4.8%8.8CVE-2021-44142Samba vfs_fruit heap out-of-bounds read/write enables code executionSamba's vfs_fruit module mishandles extended file attributes (xattr), allowing out-of-bounds heap reads and writes when specially crafted EAs are pro…EPSS 73%analysed8.8CVE-2018-14653Redhat gluster storage heap-based buffer overflow vulnerabilityThe Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_…EPSS 2.8%8.8CVE-2018-10928Debian linux link following vulnerabilityA flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gl…EPSS 2.7%8.8CVE-2011-3045Google chrome integer overflow vulnerabilityInteger signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and oth…EPSS 3.6%8.1CVE-2020-25717Samba improper input validation vulnerabilityA flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalat…EPSS 1.6%8.1CVE-2018-1127Redhat gluster storage insufficient session expiration vulnerabilityTendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2019-3831), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.