ZeroHour

CVE-2018-1072

CVSS 3.0
9.8 critical
EPSS
<1%p61
Published
()
Modified
Description

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

Vendors
ovirtredhat
Products
ovirt, enterprise virtualization manager
Weakness
CWE-532
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.