CVE-2022-2805: Medium severity red hat enterprise virtualization vulnerability
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.
Other sources
A flaw was found in ovirt-engine. The admin password is logged unfiltered when using otopi-style.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2805?
CVE-2022-2805 is a vulnerability found in ovirt-engine that allows plaintext passwords to be logged in the log file when using otapi-style, leading to confidentiality loss.
How does CVE-2022-2805 affect the affected software?
CVE-2022-2805 affects the ovirt-engine package versions up to 4.5.3 and ovirt-engine-dwh, ovirt-engine-ui-extensions, and ovirt-web-ui packages versions up to 0:4.5.3.2-1.el8e and 0:1.3.6-1.el8e respectively, causing confidentiality loss.
What is the severity of CVE-2022-2805?
CVE-2022-2805 has a severity value of 6.5 (medium).
How can I fix CVE-2022-2805?
To fix CVE-2022-2805, upgrade the ovirt-engine package to version 4.5.3 or later, and upgrade the ovirt-engine-dwh, ovirt-engine-ui-extensions, and ovirt-web-ui packages to versions 0:4.5.3.2-1.el8e or later, 0:1.3.6-1.el8e or later, and 0:1.9.2-1.el8e or later respectively.
Where can I find more information about CVE-2022-2805?
You can find more information about CVE-2022-2805 in the following references: [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2022:8502), [CVE-2022-2805](https://access.redhat.com/security/cve/cve-2022-2805), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2079545).