CVE-2018-1073
19.06.2018, 12:29
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.Enginsight
Vendor | Product | Version |
---|---|---|
ovirt | ovirt-engine | 𝑥 < 4.2.3 |
redhat | virtualization | 4.0 |
redhat | virtualization_host | 4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-209 - Generation of Error Message Containing Sensitive InformationThe software generates an error message that includes sensitive information about its environment, users, or associated data.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.