CVE-2018-1117: Critical severity ovirt ansible roles vulnerability
Due to a missing nolog directive, the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosed admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.
Other sources
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing nolog directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2018-1117
What is the severity of CVE-2018-1117?
The severity of CVE-2018-1117 is critical with a CVSS score of 9.8.
Which software is affected by CVE-2018-1117?
The ovirt-ansible-roles package before version 1.0.6 is affected by CVE-2018-1117.
How can I fix CVE-2018-1117?
To fix CVE-2018-1117, update the ovirt-ansible-roles package to version 1.0.6 or higher.
Where can I find more information about CVE-2018-1117?
You can find more information about CVE-2018-1117 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/104186), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:1452), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1117).