Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m833-87vf-576c

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.6

Описание

ovirt-engine Logs Plaintext Passwords To File

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.

Пакеты

Наименование

org.ovirt.engine.sdk:ovirt-engine-sdk-java

maven
Затронутые версииВерсия исправления

< 4.1.7.6

4.1.7.6

EPSS

Процентиль: 56%
0.00344
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 7.2
redhat
около 8 лет назад

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.

CVSS3: 7.2
nvd
больше 7 лет назад

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.

EPSS

Процентиль: 56%
0.00344
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-532