PT-2018-5770 · Ovirt · Ovirt Engine
Publicado
2018-07-27
·
Atualizado
2022-05-13
·
CVE-2017-15113
CVSS v3.1
7.2
Alta
| Vetor | AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ovirt-engine versions prior to 4.1.7.6
Description:
The issue allows passwords to be included in log files without masking when the log level is set to DEBUG. This poses a risk when debug-level logs are shared with external parties for troubleshooting purposes. Only administrators can change the log level and access the logs.
Recommendations:
For versions prior to 4.1.7.6, update to version 4.1.7.6 or later to resolve the issue. As a temporary workaround, consider setting the log level to a level other than DEBUG to prevent passwords from being logged, and restrict access to log files to minimize the risk of password exposure.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ovirt Engine