Back

CRITICAL

no_log directive: passwords revealed in ansible log when provisioning new provider

Published Jun 19, 2018

Description

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

Affected products

Remediation

Red Hat statement

This is a Low impact vulnerability in Red Hat Enterprise Virtualization. The 'Add oVirt Provider to ManageIQ/CloudForms' Ansible playbook, part of `ovirt-ansible-roles`, inadvertently logs administrative passwords due to a missing `no_log` directive. Exploitation requires an attacker to have access to these provisioning logs, which are typically restricted to administrators, limiting the attack surface.

Red Hat mitigation

To mitigate the risk of administrative password disclosure, ensure that system logs, particularly those generated during oVirt provider provisioning, are protected with strict access controls. Limit access to these logs to authorized personnel only and avoid sharing them with untrusted systems or users.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 19, 2018
Updated Aug 5, 2024
Reserved Dec 4, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 15, 2018