oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/92665 | vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1363816 | issue tracking |
https://www.ovirt.org/release/4.0.3/ | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1369793 | issue tracking |