PT-2018-10069 · Ovirt · Ovirt Engine
Doran Moppert
·
Published
2018-06-19
·
Updated
2020-12-08
·
CVE-2018-1073
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
oVirt Engine versions prior to 4.2.3
Description
The web console login form in oVirt Engine returned different errors for non-existent users and invalid passwords. This allowed an attacker to discover the names of valid user accounts by exploiting the difference in error responses.
Recommendations
For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue.
Fix
Generation of Error Message Containing Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ovirt Engine