Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1553522 - (CVE-2018-1072) CVE-2018-1072 ovirt-engine-setup: unfiltered db password in engine-backup log
CVE-2018-1072 ovirt-engine-setup: unfiltered db password in engine-backup log
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20180626,reported=2...
: Security
Depends On: 1558798 1558799 1558812
Blocks: 1542511
  Show dependency treegraph
 
Reported: 2018-03-08 20:43 EST by Doran Moppert
Modified: 2018-07-18 11:50 EDT (History)
18 users (show)

See Also:
Fixed In Version: oVirt 4.2.2
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in ovirt-engine. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2071 None None None 2018-06-27 06:02 EDT

  None (edit)
Description Doran Moppert 2018-03-08 20:43:06 EST
The ovirt-engine-provisiondb utility, which is called by engine-backup if invoked with one of the options --provision*db, logs the username and password of the db user without redaction.
Comment 1 Doran Moppert 2018-03-08 20:43:15 EST
Acknowledgments:

Name: Yedidyah Bar David (Red Hat)
Comment 5 Doran Moppert 2018-06-26 00:49:42 EDT
External References:

https://bugzilla.redhat.com/show_bug.cgi?id=1540622
Comment 6 errata-xmlrpc 2018-06-27 06:02:24 EDT
This issue has been addressed in the following products:

  Red Hat Virtualization Engine 4.2

Via RHSA-2018:2071 https://access.redhat.com/errata/RHSA-2018:2071

Note You need to log in before you can comment on or make changes to this bug.