CVE-2018-1000018: High severity ovirt vulnerability
Published Jan 24, 2018
·Updated
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
Affected Software
1 affected component
Ovirt ovirt-hosted-engine-setup<2.2.7
Event History
Jan 24, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-1000018?
CVE-2018-1000018 is an information disclosure vulnerability in ovirt-hosted-engine-setup prior to version 2.2.7.
2
How severe is CVE-2018-1000018?
CVE-2018-1000018 has a severity score of 7.8, which is considered high.
3
What is the affected software for CVE-2018-1000018?
The affected software for CVE-2018-1000018 is Ovirt Ovirt-hosted-engine-setup prior to version 2.2.7.
4
How can I fix CVE-2018-1000018?
To fix CVE-2018-1000018, update ovirt-hosted-engine-setup to version 2.2.7 or later.
5
Is there any additional information about CVE-2018-1000018?
Yes, you can find additional information about CVE-2018-1000018 in the references provided: https://bugzilla.redhat.com/show_bug.cgi?id=1536941 and https://gerrit.ovirt.org/#/c/86635/