Information Disclosure in oVirt Engine by Red Hat
CVE-2017-15113
7.2HIGH
What is CVE-2017-15113?
The oVirt Engine, specifically versions prior to 4.1.7.6, exhibits a vulnerability where passwords are logged in plain text when the log level is set to DEBUG. This situation arises from administrators having the ability to change the log level, leading to potential exposure of sensitive information if these debug logs are inadvertently shared with third parties for troubleshooting. Such exposure raises significant security concerns as it can facilitate unauthorized access to accounts and compromise the integrity of the system.
Affected Version(s)
ovirt-engine 4.1.7.6