PT-2018-10065 · Ovirt · Ovirt Engine

Doran Moppert

·

Publicado

2018-06-26

·

Atualizado

2019-10-09

·

CVE-2018-1072

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ovirt-engine versions prior to 4.2.2
Description The issue allows for information exposure through log files. When the engine-backup command is run with certain options, such as --provision*db, the database username and password are logged in cleartext. This could lead to database passwords being leaked if the provisioning log is shared.
Recommendations For versions prior to 4.2.2, update to version 4.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the provisioning log to minimize the risk of exploitation. Avoid sharing the provisioning log until the issue is resolved.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1072
RHSA-2018:2071

Produtos afetados

Ovirt Engine