[ovirt-users] Re: Internal pentest result : Ovirt-engine authentication bypass

2024-02-13 Thread Jirka Simon
HiĀ  Sandro, Thank you a lot. Jirka On 2/12/24 13:20, Sandro Bonazzola wrote: Hi, thanks for reporting. An advisory has been published: https://github.com/oVirt/ovirt-engine/security/advisories/GHSA-5p2q-85hp-rvxg and the fix has been released in ovirt-engine-4.5.6:

[ovirt-users] Re: Internal pentest result : Ovirt-engine authentication bypass

2024-02-12 Thread Sandro Bonazzola
Hi, thanks for reporting. An advisory has been published: https://github.com/oVirt/ovirt-engine/security/advisories/GHSA-5p2q-85hp-rvxg and the fix has been released in ovirt-engine-4.5.6: https://github.com/oVirt/ovirt-engine/releases/tag/ovirt-engine-4.5.6 Builds are on their way to the mirrors.

[ovirt-users] Re: Internal pentest result : Ovirt-engine authentication bypass

2024-01-15 Thread Sandro Bonazzola
Thanks for the report Jirka, I forwarded your email to secur...@ovirt.org ; they'll investigate on your report and get back to you eventually. Il giorno lun 15 gen 2024 alle ore 10:09 Jirka Simon ha scritto: > Hello ovirt comunity. > > We had an internal pentest here and one finding is > >