Red Hat Bugzilla – Bug 1553529
CVE-2018-1074 ovirt-engine: API exposes power management credentials to administrators
Last modified: 2018-07-18 11:50:37 EDT
The ovirt-engine API and administration web portal exposed Power Management credentials including cleartext passwords to Host Administrators.
Doran, which version is affected by this bug? Has this issue been already fixed? This bug has no useful information for addressing the issue. Is the issue handled in bug #1553207 ? I have no access to it.
This issue was addressed in Red Hat Virtualization Manager (ovirt-engine) 4.1.11 via: https://access.redhat.com/errata/RHBA-2018:1219