PT-2018-10069 · Ovirt · Ovirt Engine

Doran Moppert

·

Publicado

2018-06-19

·

Atualizado

2020-12-08

·

CVE-2018-1073

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions oVirt Engine versions prior to 4.2.3
Description The web console login form in oVirt Engine returned different errors for non-existent users and invalid passwords. This allowed an attacker to discover the names of valid user accounts by exploiting the difference in error responses.
Recommendations For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue.

Correção

Generation of Error Message Containing Sensitive Information

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1073
RHSA-2018:1525

Produtos afetados

Ovirt Engine