Back

MEDIUM

ovirt-engine: DWH_DB_PASSWORD is in cleartext in the log files

Published Apr 20, 2017

Description

oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 20, 2017
Updated Aug 6, 2024
Reserved Jul 26, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 26, 2016