An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1536941 | issue tracking exploit third party advisory |
https://gerrit.ovirt.org/#/c/86635/ | vendor advisory |