Unrated severityNVD Advisory· Published Jun 12, 2018· Updated Aug 5, 2024
CVE-2018-1075
CVE-2018-1075
Description
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
Affected products
1- Range: <=4.2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- access.redhat.com/errata/RHSA-2018:2071mitrevendor-advisoryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- gerrit.ovirt.orgmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.