PT-2022-18777 · Ovirt · Ovirt Engine

Pedro Sampaio

·

Published

2022-10-19

·

Updated

2025-05-09

·

CVE-2022-2805

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions oVirt Engine (affected versions not specified)
Description A flaw in oVirt Engine causes plaintext passwords to be logged in the log file when using otapi-style, potentially leading to confidentiality loss if an attacker with sufficient privileges reads the log file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-2805
RHSA-2022:8502

Affected Products

Ovirt Engine