ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.
References
Link | Resource |
---|---|
https://gerrit.ovirt.org/gitweb?p=ovirt-engine.git;a=commitdiff;h=f4a5d0cc772127dbfe40789e26c4633ceea07d14;hp=e6e8704ac9eb115624ff66e2965877d8e63a45f4 | Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15113 | Issue Tracking Patch Third Party Advisory |
https://access.redhat.com/errata/RHEA-2017:3138 | Third Party Advisory |
http://www.securityfocus.com/bid/101933 | Third Party Advisory VDB Entry |
Information
Published : 2018-07-27 09:29
Updated : 2019-10-09 16:24
NVD link : CVE-2017-15113
Mitre link : CVE-2017-15113
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
redhat
- virtualization
ovirt
- ovirt