HIGH
ovirt-hosted-engine-setup: root password exposed in log file
Published Jan 24, 2018
7.8
HIGHCVSS 3.0
EPSS 0.41%
Description
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
Affected products
No data.
- < 2.2.7
No data.
Red Hat Virtualization 4
ovirt-hosted-engine-setup
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Virtualization 4 | ovirt-hosted-engine-setup | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Released versions of Red Hat Enterprise Virtualization were not impacted by this issue in practice as the passwords were not saved in the answerfile during provisioning.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2018-1000018 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1536941 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1537904 Issue Tracking
- https://gerrit.ovirt.org/#/c/62679/
- https://gerrit.ovirt.org/#/c/86635/ x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000018
- https://www.cve.org/CVERecord?id=CVE-2018-1000018
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1000018 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1536941 | x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1537904 | Issue Tracking | |
| https://gerrit.ovirt.org/#/c/62679/ | ||
| https://gerrit.ovirt.org/#/c/86635/ | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000018 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000018 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 24, 2018
Updated Sep 17, 2024
Reserved Jan 24, 2018
Link CVE-2018-1000018
CISA Vulnrichment
Updated n/a