Red Hat Bugzilla – Bug 1542508
CVE-2018-1075 ovirt-engine: Unfiltered password when choosing manual db provisioning
Last modified: 2018-07-18 11:46:36 EDT
A flaw was found in ovirt-engine. When engine-setup is run and one chooses to provision the database manually or connect to a remote database, the password input is logged but filtered only later, after verification that it is correct. References: https://bugzilla.redhat.com/show_bug.cgi?id=1540622
Didi can you please push the fixes to gerrit?
https://gerrit.ovirt.org/91653 Added it to external trackers of bug 1558813.
Acknowledgments: Name: Yedidyah Bar David (Red Hat)
This issue has been addressed in the following products: Red Hat Virtualization Engine 4.2 Via RHSA-2018:2071 https://access.redhat.com/errata/RHSA-2018:2071