ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-11727 ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T03:51:48.553Z

Reserved: 2017-12-04T00:00:00

Link: CVE-2018-1075

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-12T13:29:00.347

Modified: 2024-11-21T03:59:07.690

Link: CVE-2018-1075

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-05-29T00:00:00Z

Links: CVE-2018-1075 - Bugzilla

cve-icon OpenCVE Enrichment

No data.