CVE-2014-3561Sensitive Information Exposure in Redhat Enterprise Virtualization

Severity
2.1LOWNVD
EPSS
0.1%
top 81.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 5
Latest updateMay 17

Description

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-xxxj-4ccj-cfw9: The rhevm-log-collector package in Red Hat Enterprise Virtualization 32022-05-17
CVEList
CVE-2014-3561: The rhevm-log-collector package in Red Hat Enterprise Virtualization 32014-12-05

📋Vendor Advisories

1
Red Hat
ovirt-engine-log-collector: database password disclosed in process listing2014-12-02

💬Community

1
Bugzilla
CVE-2014-3561 ovirt-engine-log-collector: database password disclosed in process listing2014-07-24
CVE-2014-3561 — Sensitive Information Exposure | cvebase