CVE-2018-1075

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ovirt:ovirt:*:*:*:*:*:*:*:*

History

13 Feb 2023, 04:53

Type Values Removed Values Added
CWE CWE-522
Summary A flaw was found in ovirt-engine. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords. ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2018-1075', 'name': 'https://access.redhat.com/security/cve/CVE-2018-1075', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1542508', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1542508', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 21:18

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2018-1075 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1542508 -
Summary ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords. A flaw was found in ovirt-engine. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

Information

Published : 2018-06-12 13:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-1075

Mitre link : CVE-2018-1075

CVE.ORG link : CVE-2018-1075


JSON object : View

Products Affected

ovirt

  • ovirt
CWE
CWE-532

Insertion of Sensitive Information into Log File

CWE-522

Insufficiently Protected Credentials