First published: Fri May 04 2018(Updated: )
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ovirt-ansible-roles | <1.0.6 | 1.0.6 |
Ovirt Ovirt-ansible-roles | <1.0.6 | |
Redhat Enterprise Virtualization | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1117
The severity of CVE-2018-1117 is critical with a CVSS score of 9.8.
The ovirt-ansible-roles package before version 1.0.6 is affected by CVE-2018-1117.
To fix CVE-2018-1117, update the ovirt-ansible-roles package to version 1.0.6 or higher.
You can find more information about CVE-2018-1117 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/104186), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:1452), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1117).