CVE-2017-15113
27.07.2018, 16:29
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.Enginsight
Vendor | Product | Version |
---|---|---|
ovirt | ovirt | 𝑥 < 4.1.7.6 |
redhat | virtualization | 4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-212 - Improper Removal of Sensitive Information Before Storage or TransferThe product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
- CWE-532 - Insertion of Sensitive Information into Log FileInformation written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
References