Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1117

Опубликовано: 20 июн. 2018
Источник: nvd
CVSS3: 5
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ovirt:ovirt-ansible-roles:*:*:*:*:*:*:*:*
Версия до 1.0.6 (исключая)
Конфигурация 2
cpe:2.3:o:redhat:enterprise_virtualization:4.1:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00203
Низкий

5 Medium

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-532
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5
redhat
больше 7 лет назад

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

CVSS3: 9.8
github
больше 3 лет назад

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

EPSS

Процентиль: 42%
0.00203
Низкий

5 Medium

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-532
NVD-CWE-noinfo