Описание
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
Ссылки
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:redhat:ovirt-engine:4.1.0:-:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.00253
Низкий
8.8 High
CVSS3
4 Medium
CVSS2
Дефекты
CWE-200
CWE-522
Связанные уязвимости
CVSS3: 6.5
redhat
больше 8 лет назад
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
CVSS3: 8.8
github
больше 3 лет назад
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
EPSS
Процентиль: 48%
0.00253
Низкий
8.8 High
CVSS3
4 Medium
CVSS2
Дефекты
CWE-200
CWE-522