Vulnerability Description
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sos Project | Sos | < 4.2-20.el8_6 |
| Ovirt | Log Collector | < 4.4.7-2.el8ev |
Related Weaknesses (CWE)
References
- https://github.com/sosreport/sos/pull/2947PatchThird Party Advisory
- https://github.com/sosreport/sos/pull/2947PatchThird Party Advisory
FAQ
What is CVE-2022-2806?
CVE-2022-2806 is a vulnerability with a CVSS score of 5.5 (MEDIUM). It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
How severe is CVE-2022-2806?
CVE-2022-2806 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2806?
Check the references section above for vendor advisories and patch information. Affected products include: Sos Project Sos, Ovirt Log Collector.