ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
The product writes sensitive information to a log file.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1075 | issue tracking third party advisory |
https://gerrit.ovirt.org/#/c/91653/ | vendor advisory |
https://access.redhat.com/errata/RHSA-2018:2071 | third party advisory vendor advisory |