MEDIUM
ovirt-log-collector: RHVM admin password is logged unfiltered
Published Sep 1, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
Affected products
- Vendor n/a Product Ovirt-Log-Collector Defaultn/a
- Version sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8evStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ovirt-Log-Collector | n/a |
|
Configuration 1
- < 4.2-20.el8_6
Configuration 2
- < 4.4.7-2.el8ev
No data.
Red Hat Virtualization Engine 4.4
ovirt-log-collector-0:4.4.7-2.el8ev
Fixed · RHSA-2022:6393
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Virtualization Engine 4.4 | ovirt-log-collector-0:4.4.7-2.el8ev | Fixed | RHSA-2022:6393 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2022-2806 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2080005 Issue Tracking
- https://github.com/advisories/GHSA-7pf9-7cff-f854 Advisory
- https://github.com/sosreport/sos/commit/5fd872c64c53af37015f366295e0c2418c969757
- https://github.com/sosreport/sos/pull/2947 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2806
- https://www.cve.org/CVERecord?id=CVE-2022-2806
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2806 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2080005 | Issue Tracking | |
| https://github.com/advisories/GHSA-7pf9-7cff-f854 | Advisory | |
| https://github.com/sosreport/sos/commit/5fd872c64c53af37015f366295e0c2418c969757 | ||
| https://github.com/sosreport/sos/pull/2947 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2806 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2806 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 1, 2022
Updated Aug 3, 2024
Reserved Aug 12, 2022
Link CVE-2022-2806
CISA Vulnrichment
GHSA-7PF9-7CFF-F854 Updated n/a