CVE-2016-6310: Infoleak
It was reported that the contents of the ENGINEHTTPSPKITRUSTSTOREPASSWORD environment variable set by ovirt-engine are exposed in the /var/log/ovirt-engine/engine.log file.
Other sources
oVirt Engine discloses the ENGINEHTTPSPKITRUSTSTOREPASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6310?
CVE-2016-6310 is considered a high severity vulnerability due to the exposure of sensitive credential information.
How do I fix CVE-2016-6310?
To fix CVE-2016-6310, ensure that the environment variable ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD is not logged and consider updating to the latest patched version of oVirt Engine.
What versions of oVirt Engine are affected by CVE-2016-6310?
CVE-2016-6310 affects Red Hat Enterprise Virtualization versions up to and including 3.6.
What data is exposed in CVE-2016-6310?
CVE-2016-6310 exposes the contents of the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD environment variable in the engine.log file.
Is CVE-2016-6310 a critical vulnerability?
While CVE-2016-6310 is high severity, it is not classified as critical but poses a significant security risk due to password exposure.