CVE-2018-1074: Infoleak
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1074?
CVE-2018-1074 is a vulnerability in the ovirt-engine API and administration web portal, which allows an exposure of Power Management credentials, including cleartext passwords to Host Administrators.
What is the severity of CVE-2018-1074?
The severity of CVE-2018-1074 is high with a severity value of 7.2.
Which software versions are affected by CVE-2018-1074?
Versions 4.2.2.5 and 4.1.11.2 of the ovirt-engine API and administration web portal are affected.
How can a Host Administrator exploit CVE-2018-1074?
A Host Administrator can exploit CVE-2018-1074 to gain access to the power management systems of hosts and view Power Management credentials, including cleartext passwords.
Is there a fix available for CVE-2018-1074?
Yes, the fix for CVE-2018-1074 is available in versions 4.2.2.5 and 4.1.11.2 of the ovirt-engine API and administration web portal.