First published: Wed Jan 24 2018(Updated: )
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ovirt Ovirt-hosted-engine-setup | <2.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000018 is an information disclosure vulnerability in ovirt-hosted-engine-setup prior to version 2.2.7.
CVE-2018-1000018 has a severity score of 7.8, which is considered high.
The affected software for CVE-2018-1000018 is Ovirt Ovirt-hosted-engine-setup prior to version 2.2.7.
To fix CVE-2018-1000018, update ovirt-hosted-engine-setup to version 2.2.7 or later.
Yes, you can find additional information about CVE-2018-1000018 in the references provided: https://bugzilla.redhat.com/show_bug.cgi?id=1536941 and https://gerrit.ovirt.org/#/c/86635/