CVE-2018-1075: High severity ovirt vulnerability
A flaw was found in ovirt-engine. When engine-setup is run and one chooses to provision the database manually or connect to a remote database, the password input is logged but filtered only later, after verification that it is correct.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1540622
Other sources
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1075?
CVE-2018-1075 is a vulnerability in ovirt-engine up to version 4.2.3 that allows an unfiltered password to be logged in cleartext during the verification step of manual database provisioning.
How severe is CVE-2018-1075?
CVE-2018-1075 has a severity score of 7.8 (high).
What software is affected by CVE-2018-1075?
ovirt-engine up to version 4.2.3 is affected by CVE-2018-1075.
How can I fix CVE-2018-1075?
To fix CVE-2018-1075, upgrade to a version of ovirt-engine that is higher than 4.2.3.
Are there any references for CVE-2018-1075?
Yes, you can find references for CVE-2018-1075 at the following links: [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:2071), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1075), and [ovirt Gerrit](https://gerrit.ovirt.org/#/c/91653/).