5
CVSSv2

CVE-2018-1072

Published: 26/06/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ovirt ovirt

redhat enterprise virtualization manager 4.2

Vendor Advisories

Synopsis Moderate: Red Hat Virtualization Manager security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for orgovirtengine-root is now available for Red Hat Virtualization Manager 42Red Hat Product Security has rated this update as having a security impact o ...
A flaw was found in ovirt-engine When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext Sharing the provisioning log might inadvertently leak database passwords ...