Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1075

Опубликовано: 29 мая 2018
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

A flaw was found in ovirt-engine. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-532
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1542508ovirt-engine: Unfiltered password when choosing manual db provisioning

EPSS

Процентиль: 12%
0.00043
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
nvd
около 7 лет назад

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

CVSS3: 7.8
github
больше 3 лет назад

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

EPSS

Процентиль: 12%
0.00043
Низкий

5 Medium

CVSS3