ovirt-engine: RHVM admin password is logged unfiltered when using otopi-style
Published Oct 19, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.44%
Description
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.
Affected products
- Vendor n/a Product Ovirt-Engine Defaultn/a
- Version ovirt-engine 4.5.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ovirt-Engine | n/a |
|
- 4.0
No data.
Red Hat Virtualization Engine 4.4
ovirt-engine-0:4.5.3.2-1.el8ev
Fixed · RHSA-2022:8502
Red Hat Virtualization Engine 4.4
ovirt-engine-dwh-0:4.5.7-1.el8ev
Fixed · RHSA-2022:8502
Red Hat Virtualization Engine 4.4
ovirt-engine-ui-extensions-0:1.3.6-1.el8ev
Fixed · RHSA-2022:8502
Red Hat Virtualization Engine 4.4
ovirt-web-ui-0:1.9.2-1.el8ev
Fixed · RHSA-2022:8502
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Virtualization Engine 4.4 | ovirt-engine-0:4.5.3.2-1.el8ev | Fixed | RHSA-2022:8502 |
| Red Hat Virtualization Engine 4.4 | ovirt-engine-dwh-0:4.5.7-1.el8ev | Fixed | RHSA-2022:8502 |
| Red Hat Virtualization Engine 4.4 | ovirt-engine-ui-extensions-0:1.3.6-1.el8ev | Fixed | RHSA-2022:8502 |
| Red Hat Virtualization Engine 4.4 | ovirt-web-ui-0:1.9.2-1.el8ev | Fixed | RHSA-2022:8502 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://access.redhat.com/security/cve/CVE-2022-2805 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2079545 Issue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2805
- https://www.cve.org/CVERecord?id=CVE-2022-2805
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2805 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2079545 | Issue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2805 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2805 |
Change history (0)
No recorded changes yet.