First published: Fri Mar 09 2018(Updated: )
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ovirt-engine | <4.2.3 | 4.2.3 |
Ovirt Ovirt-engine | <4.2.3 | |
Redhat Virtualization | =4.0 | |
Redhat Virtualization Host | =4.0 | |
Redhat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-1073.
The severity level of CVE-2018-1073 is medium with a CVSS score of 5.3.
The affected software includes ovirt-engine versions up to exclusive 4.2.3, Ovirt Ovirt-engine versions up to exclusive 4.2.3, Redhat Virtualization 4.0, and Redhat Virtualization Host 4.0.
An attacker can exploit this vulnerability by discovering the names of valid user accounts through the web console login form in ovirt-engine.
Yes, the fix for CVE-2018-1073 is available in ovirt-engine version 4.2.3.