CVE-2019-10139: High severity ovirt vulnerability
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file /var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-10139?
CVE-2019-10139 is a vulnerability during HE deployment via cockpit-ovirt, where cockpit-ovirt generates an ansible variable file containing plain-text admin and appliance passwords.
How does CVE-2019-10139 affect the software?
CVE-2019-10139 affects cockpit-ovirt version 0.13.5-1.el7e and earlier.
What is the severity of CVE-2019-10139?
CVE-2019-10139 has a severity rating of 7.8 (High).
How can I fix CVE-2019-10139?
To fix CVE-2019-10139, upgrade to cockpit-ovirt version 0.13.5-1.el7e or later.
Where can I find more information about CVE-2019-10139?
You can find more information about CVE-2019-10139 at the following references: - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1703678) - [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2019:2433) - [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2019:2437)