Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1072

Опубликовано: 26 июн. 2018
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provisiondb", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

A flaw was found in ovirt-engine. When engine-backup was run with one of the options "--provision
db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

Дополнительная информация

Статус:

Low
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1553522ovirt-engine-setup: unfiltered db password in engine-backup log

EPSS

Процентиль: 35%
0.00146
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
nvd
больше 7 лет назад

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

CVSS3: 9.8
github
больше 3 лет назад

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

EPSS

Процентиль: 35%
0.00146
Низкий

5 Medium

CVSS3