CVE-2022-2806: Infoleak
A flaw was found in the ovirt-log-collector, which led to the logging of plaintext passwords in the log file. This flaw allows an attacker with sufficient privileges to read the log file, leading to a loss of confidentiality.
Other sources
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el86, ovirt-log-collector-4.4.7-2.el8ev
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-2806?
CVE-2022-2806 is a vulnerability found in the oVirt Log Collector and SOS report tool, which logs plaintext passwords in the log file, allowing attackers with sufficient privileges to read the log file and access confidential information.
What is the severity of CVE-2022-2806?
CVE-2022-2806 has a severity of medium with a CVSS score of 5.1 (out of 10).
How does CVE-2022-2806 affect the affected software?
CVE-2022-2806 affects the ovirt-log-collector and sos packages with specific versions installed.
How can CVE-2022-2806 be fixed?
To fix CVE-2022-2806, update the affected software versions to the specific remediation versions provided by Red Hat.
Where can I find more information about CVE-2022-2806?
More information about CVE-2022-2806 can be found in the reference links provided by Red Hat.