REDHAT-BUG-1371428: Medium severity Ovirt oVirt Engine vulnerability
When ovirt-engine-provisiondb, a utility usually called by engine-backup, was passed one of the '--provisiondb' options to create postgresql DBs/users, the password of the created user is stored in the log file in plain text.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1371428?
The severity of REDHAT-BUG-1371428 is considered high due to the exposure of sensitive information in log files.
How do I fix REDHAT-BUG-1371428?
To fix REDHAT-BUG-1371428, it is recommended to update to the latest version of oVirt Engine that addresses this logging issue.
What vulnerable component is highlighted in REDHAT-BUG-1371428?
REHAT-BUG-1371428 highlights the ovirt-engine-provisiondb utility as the vulnerable component.
What information is leaked in REDHAT-BUG-1371428?
REHAT-BUG-1371428 results in the passwords for created PostgreSQL users being stored in plain text within log files.
Is REDHAT-BUG-1371428 a remote exploit risk?
REHAT-BUG-1371428 poses a risk primarily for local access since the logs are stored on the system where the utility is run.