Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15113

Опубликовано: 13 нояб. 2017
Источник: redhat
CVSS3: 7.2

Описание

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Virtualization 3ovirt-engineWill not fix
Red Hat Virtualization Engine 4.1org.ovirt.engine-rootFixedRHEA-2017:313807.11.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-212
https://bugzilla.redhat.com/show_bug.cgi?id=1512365ovirt-engine: DEBUG logging includes unmasked passwords

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
больше 7 лет назад

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.

CVSS3: 6.6
github
больше 3 лет назад

ovirt-engine Logs Plaintext Passwords To File

7.2 High

CVSS3