ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.
2018-06-26T18:29:00.607
2024-11-21T03:59:07.290
Modified
CVSSv3.0: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ovirt | ovirt | < 4.2.2 | Yes |
Application | redhat | enterprise_virtualization_manager | 4.2 | Yes |