The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1073 | issue tracking third party advisory |
http://www.securityfocus.com/bid/104189 | vdb entry third party advisory |
https://access.redhat.com/errata/RHSA-2018:1525 | third party advisory vendor advisory |