oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-1780 | third party advisory issue tracking |
https://access.redhat.com/security/cve/cve-2015-1780 | third party advisory |