Vulnerability record · CVE-2018-1075 · published 12 June 2018
CVE-2018-1075: Ovirt sensitive information in log file vulnerability
Ovirt · Ovirt
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
Description
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2018:2071 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1075 | Issue TrackingThird Party Advisory |
| https://gerrit.ovirt.org/#/c/91653/ | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2018:2071 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1075 | Issue TrackingThird Party Advisory |
| https://gerrit.ovirt.org/#/c/91653/ | Vendor Advisory |
Track CVE-2018-1075 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1075), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.