High severity7.8NVD Advisory· Published May 17, 2019· Updated Jun 17, 2026
CVE-2019-10139
CVE-2019-10139
Description
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file /var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:ovirt:cockpit-ovirt:-:*:*:*:*:*:*:*
- ovirt/cockpit-ovirtv5Range: n/a
Patches
Vulnerability mechanics
References
4- www.securityfocus.com/bid/108396nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2019:2433nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2437nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.