Red Hat Bugzilla – Bug 1537904
CVE-2018-1000018 ovirt-hosted-engine-setup: root password exposed in log file
Last modified: 2018-01-24 00:59:41 EST
It was found that ovirt-hosted-engine-setup did not correctly filter cloudInitRootPwd from the setup log file, exposing it in clear text where local users could potentially read it. Statement: Released versions of Red Hat Enterprise Virtualization were not impacted by this issue in practice as the passwords were not saved in the answerfile during provisioning.
Product bug, raised against RHV 4.2 beta: https://bugzilla.redhat.com/show_bug.cgi?id=1536941
External References: https://gerrit.ovirt.org/#/c/86635/ https://gerrit.ovirt.org/#/c/62679/