ovirt-engine Logs Plaintext Passwords To File
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Aug 18, 2023
Withdrawn
This advisory was withdrawn on Aug 18, 2023
Package
Affected versions
< 4.1.7.6
Patched versions
4.1.7.6
Description
Published by the National Vulnerability Database
Jul 27, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 25, 2023
Last updated
Aug 18, 2023
Withdrawn
Aug 18, 2023
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.
References