Vulnerability Description
A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ovirt | Vdsm | >= 4.30.1, < 4.50.0.4 |
| Redhat | Virtualization | 4.0 |
| Redhat | Virtualization For Ibm Power Little Endian | 4.0 |
| Redhat | Virtualization Host | 4.0 |
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2022-0207Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2033697Issue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2039248Issue TrackingThird Party Advisory
- https://gerrit.ovirt.org/c/vdsm/+/118025PatchVendor Advisory
- https://gerrit.ovirt.org/gitweb?p=vdsm.git%3Ba=commit%3Bh=53b0036fc72d3b8877d4e7
- https://access.redhat.com/security/cve/CVE-2022-0207Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2033697Issue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2039248Issue TrackingThird Party Advisory
- https://gerrit.ovirt.org/c/vdsm/+/118025PatchVendor Advisory
- https://gerrit.ovirt.org/gitweb?p=vdsm.git%3Ba=commit%3Bh=53b0036fc72d3b8877d4e7
FAQ
What is CVE-2022-0207?
CVE-2022-0207 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
How severe is CVE-2022-0207?
CVE-2022-0207 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0207?
Check the references section above for vendor advisories and patch information. Affected products include: Ovirt Vdsm, Redhat Virtualization, Redhat Virtualization For Ibm Power Little Endian, Redhat Virtualization Host, Redhat Enterprise Linux.