Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat oVirt Engine 信息泄露漏洞
Vulnerability Description
Red Hat oVirt Engine是美国红帽(Red Hat)公司的一套开源的虚拟化管理平台,是RHEV(企业虚拟化平台)的开源版本,由ovirt-node客户端和overt-engine管理端组成。 oVirt Engine 4.0.3之前的版本中存在安全漏洞,该漏洞源于日志文件中没有正确隐藏包含密钥清单的DWH_DB_PASSWORD。本地攻击者可通过读取引擎日志文件利用该漏洞获取敏感的密码信息。
CVSS Information
N/A
Vulnerability Type
N/A