Red Hat Bugzilla – Bug 1553522
CVE-2018-1072 ovirt-engine-setup: unfiltered db password in engine-backup log
Last modified: 2018-07-18 11:50:31 EDT
The ovirt-engine-provisiondb utility, which is called by engine-backup if invoked with one of the options --provision*db, logs the username and password of the db user without redaction.
Acknowledgments: Name: Yedidyah Bar David (Red Hat)
External References: https://bugzilla.redhat.com/show_bug.cgi?id=1540622
This issue has been addressed in the following products: Red Hat Virtualization Engine 4.2 Via RHSA-2018:2071 https://access.redhat.com/errata/RHSA-2018:2071