REDHAT-BUG-1335106: Medium severity red hat enterprise virtualization manager (rhev-m) vulnerability
It was reported that engine-setup logs for RHEV-M contained enough information for extraction of admin password for RHEV-M. Specifically, it contains output of each SQL query with encrypted admin password from the database, and the result of esch external command execution including the openssl command that extracts the private key from the p12 bundle. Having both, encrypted password and private key in the same file gives ability for everyone, who is able to read log file, to obtain admin password.
This issue was introduced with following commit:
https://gerrit.ovirt.org/#/c/43578
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1335106?
The severity of REDHAT-BUG-1335106 has been classified as high due to the exposure of sensitive information.
Who is affected by REDHAT-BUG-1335106?
The vulnerability impacts users of Red Hat Enterprise Virtualization Manager (RHEV-M) who rely on engine-setup.
How do I fix REDHAT-BUG-1335106?
To fix REDHAT-BUG-1335106, ensure that the engine-setup logs are secured and limit access to sensitive information until a patch is released.
What kind of information is leaked in REDHAT-BUG-1335106?
REDHAT-BUG-1335106 exposes the encrypted admin password and SQL query outputs from the engine-setup logs.
What should I do if I have been affected by REDHAT-BUG-1335106?
If affected by REDHAT-BUG-1335106, consider rotating your admin password and reviewing access controls immediately.