PT-2018-10069 · Ovirt · Ovirt Engine

Doran Moppert

·

Published

2018-06-19

·

Updated

2020-12-08

·

CVE-2018-1073

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions oVirt Engine versions prior to 4.2.3
Description The web console login form in oVirt Engine returned different errors for non-existent users and invalid passwords. This allowed an attacker to discover the names of valid user accounts by exploiting the difference in error responses.
Recommendations For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue.

Fix

Generation of Error Message Containing Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1073
RHSA-2018:1525

Affected Products

Ovirt Engine