← Back to CVE List

CVE-2018-1075

Published: 2018-06-12T13:29Z
Last Modified: 2024-11-21T03:59Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt