CVE-2017-15113

Description

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.

Risk Information

Base Score
6.6
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.344

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-15113 are fixed in oVirt-ovirt-engine-sdk-java 4.1.7.6Windows
Vulnerabilities CVE-2017-15113 are fixed in oVirt-ovirt-engine-sdk-java for Linux 4.1.7.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234