CVE-2018-1075

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
12/06/2018
Last modified:
13/02/2023

Description

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ovirt:ovirt:*:*:*:*:*:*:*:* 4.2.3 (excluding)