MEDIUM · 5.0

CVE-2018-1117

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin pas...

Vulnerability Description

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

CVSS Score

5.0

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OvirtOvirt-Ansible-Roles< 1.0.6
RedhatEnterprise Virtualization4.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-1117?

CVE-2018-1117 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin pas...

How severe is CVE-2018-1117?

CVE-2018-1117 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-1117?

Check the references section above for vendor advisories and patch information. Affected products include: Ovirt Ovirt-Ansible-Roles, Redhat Enterprise Virtualization.