← Vulnerability feed

Vulnerability record · CVE-2019-10194 · published 11 July 2019

CVE-2019-10194: Ovirt sensitive information in log file vulnerability

Ovirt · Ovirt

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.

5.5 CVSS 3.1 Medium EPSS 0.35% · top 74.5% CWE-532 · Sensitive information in log file
5.5CVSS 3.1 base score, v2 2.1
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/109140 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2019:2499 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10194 Issue TrackingVendor Advisory
http://www.securityfocus.com/bid/109140 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2019:2499 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10194 Issue TrackingVendor Advisory

Track CVE-2019-10194 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-17963Qemu integer overflow vulnerabilityqemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possib…EPSS 4.7%9.8CVE-2017-7481Redhat openshift container platform improper input validation vulnerabilityAnsible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku…EPSS 4.8%9.8CVE-2018-1072Ovirt sensitive information in log file vulnerabilityovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option…EPSS 0.99%9.8CVE-2017-9214Openvswitch vulnerabilityIn Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsi…EPSS 2.9%9.1CVE-2019-10744Lodash prototype pollution vulnerabilityVersions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying prop…EPSS 5.0%8.1CVE-2019-3879Ovirt missing authorization vulnerabilityIt was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission …EPSS 1.8%7.8CVE-2018-1075Ovirt sensitive information in log file vulnerabilityovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one choo…EPSS 0.35%7.5CVE-2018-16881Rsyslog integer overflow vulnerabilityA denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket,…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2019-10194), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.