Red Hat Bugzilla – Bug 1363738
CVE-2016-6310 ovirt-engine: ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD disclosed in log file
Last modified: 2016-08-26 16:15:00 EDT
It was reported that the contents of the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD environment variable set by ovirt-engine are exposed in the /var/log/ovirt-engine/engine.log file.
Acknowledgments: Name: Jiri Belka (Red Hat)
This was fixed in RHEV 4.0 GA.