Description
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11725 | The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T03:51:47.320Z
Reserved: 2017-12-04T00:00:00.000Z
Link: CVE-2018-1073
No data.
Status : Modified
Published: 2018-06-19T12:29:00.280
Modified: 2024-11-21T03:59:07.427
Link: CVE-2018-1073
OpenCVE Enrichment
No data.
EUVD