Vulnerability record · CVE-2018-1117 · published 20 June 2018
CVE-2018-1117: Ovirt-ansible-roles sensitive information in log file vulnerability
Ovirt · Ovirt Ansible Roles
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.
Description
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104186 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2018:1452 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1117 | Issue TrackingThird Party Advisory |
| http://www.securityfocus.com/bid/104186 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2018:1452 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1117 | Issue TrackingThird Party Advisory |
Track CVE-2018-1117 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1117), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.