ZeroHour

CVE-2016-6341

CVSS 3.0
5.5 medium
EPSS
<1%p28
Published
()
Modified
Description

oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.

Vendors
ovirt
Products
ovirt
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.