Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1117

Опубликовано: 15 мая 2018
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

Due to a missing no_log directive, the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosed admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

Отчет

This is a Low impact vulnerability in Red Hat Enterprise Virtualization. The 'Add oVirt Provider to ManageIQ/CloudForms' Ansible playbook, part of ovirt-ansible-roles, inadvertently logs administrative passwords due to a missing no_log directive. Exploitation requires an attacker to have access to these provisioning logs, which are typically restricted to administrators, limiting the attack surface.

Меры по смягчению последствий

To mitigate the risk of administrative password disclosure, ensure that system logs, particularly those generated during oVirt provider provisioning, are protected with strict access controls. Limit access to these logs to authorized personnel only and avoid sharing them with untrusted systems or users.

Дополнительная информация

Статус:

Low
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1574776no_log directive: passwords revealed in ansible log when provisioning new provider

EPSS

Процентиль: 71%
0.01424
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
nvd
около 8 лет назад

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

CVSS3: 9.8
github
больше 4 лет назад

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

EPSS

Процентиль: 71%
0.01424
Низкий

5 Medium

CVSS3