CVE-2016-4443: Medium severity red hat enterprise virtualization vulnerability
It was reported that engine-setup logs for RHEV-M contained enough information for extraction of admin password for RHEV-M. Specifically, it contains output of each SQL query with encrypted admin password from the database, and the result of esch external command execution including the openssl command that extracts the private key from the p12 bundle. Having both, encrypted password and private key in the same file gives ability for everyone, who is able to read log file, to obtain admin password.
This issue was introduced with following commit:
https://gerrit.ovirt.org/#/c/43578
Other sources
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4443?
CVE-2016-4443 is rated as a medium severity vulnerability due to the potential exposure of sensitive admin password information.
How do I fix CVE-2016-4443?
To fix CVE-2016-4443, update to the latest patched version of Red Hat Enterprise Virtualization that addresses this vulnerability.
What impact does CVE-2016-4443 have on RHEV-M?
CVE-2016-4443 can allow an attacker to extract the admin password from the engine-setup logs of RHEV-M.
Which versions of Red Hat Enterprise Virtualization are affected by CVE-2016-4443?
CVE-2016-4443 specifically affects Red Hat Enterprise Virtualization version 3.6.
Is there a workaround for CVE-2016-4443 before applying a patch?
There are no documented workarounds for CVE-2016-4443, so it is recommended to apply the patch as soon as it is available.