CVE-2016-6341: Infoleak
It was found that the value of property DWHDBPASSWORD can be found in the log files.
Product bug:
https://bugzilla.redhat.com/showbug.cgi?id=1363816
Other sources
oVirt Engine before 4.0.3 does not include DWHDBPASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6341?
CVE-2016-6341 has a medium severity rating due to the exposure of sensitive database passwords in log files.
How do I fix CVE-2016-6341?
To fix CVE-2016-6341, upgrade to a version of oVirt that addresses the logging issue and prevents sensitive information from being logged.
Which versions of oVirt are affected by CVE-2016-6341?
CVE-2016-6341 affects oVirt versions up to and including 4.0.2.
What information is exposed in CVE-2016-6341?
CVE-2016-6341 exposes the DWH_DB_PASSWORD property in log files, which can lead to potential unauthorized access.
Is there a workaround for CVE-2016-6341?
As a workaround for CVE-2016-6341, you can manually delete sensitive information from the logs, but updating to a secure version is recommended.