Back

MEDIUM

Ovirt-engine: potential exposure of cleartext provider passwords via web ui

Published Sep 26, 2024

Description

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Sep 26, 2024
Updated Jan 8, 2026
Reserved Jul 30, 2024

CISA Vulnrichment

Updated Sep 26, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Sep 26, 2024
Bugzilla 2314229

ENISA EUVD

Assigner redhat
Published Sep 26, 2024
Updated Jan 8, 2026

GitHub

No data