Back

HIGH

ovirt-hosted-engine-setup: root password exposed in log file

Published Jan 24, 2018

Description

An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.

Affected products

Remediation

Red Hat statement

Released versions of Red Hat Enterprise Virtualization were not impacted by this issue in practice as the passwords were not saved in the answerfile during provisioning.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 24, 2018
Updated Sep 17, 2024
Reserved Jan 24, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 24, 2018