CVE-2018-1072
published 2018-06-26CVE-2018-1072: ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options…
PriorityP342critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.99%
58.7th percentile
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | ovirt | < 4.2.2 | 4.2.2 |
| redhat | enterprise_virtualization_manager | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9fw7-mcq9-ghf3: ovirt-engine before version ovirt 4
ghsa_unreviewed·2022-05-13
CVE-2018-1072 [CRITICAL] CWE-532 GHSA-9fw7-mcq9-ghf3: ovirt-engine before version ovirt 4
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.
Red Hat
jenkins: forced migration of user records (SECURITY-1072)
vendor_redhat·2018-12-05·CVSS 8.2
CVE-2018-1000863 [HIGH] CWE-20 jenkins: forced migration of user records (SECURITY-1072)
jenkins: forced migration of user records (SECURITY-1072)
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
Package: jenkins (Red Hat OpenShift Container Platform 3.10) - Will not fix
Package: jenkins (Red Hat OpenShift Container Platform 3.2) - Will not fix
Package: jenkins (Red Hat OpenShift Container Platform 3.3) - Will not fix
Package: jenkins (Red Hat OpenShift Container Platform 3.4) - Will not fix
Package: jenkins (Red Hat OpenShift Container Platform 3.5) - Will not fix
Package: jenkins (Red Hat OpenShift Container Platfor
Red Hat
ovirt-engine-setup: unfiltered db password in engine-backup log
vendor_redhat·2018-06-26·CVSS 5.0
CVE-2018-1072 [MEDIUM] CWE-532 ovirt-engine-setup: unfiltered db password in engine-backup log
ovirt-engine-setup: unfiltered db password in engine-backup log
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.
A flaw was found in ovirt-engine. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000863 jenkins: forced migration of user records (SECURITY-1072)
bugzilla·2018-12-06·CVSS 8.2
CVE-2018-1000863 [HIGH] CVE-2018-1000863 jenkins: forced migration of user records (SECURITY-1072)
CVE-2018-1000863 jenkins: forced migration of user records (SECURITY-1072)
A flaw was found in Jenkins. The fix for SECURITY-499 introduced a mechanism that renamed user directories on disk as a user with an unsafe user name (user ID) is loaded. Insufficient input validation allowed attackers to rename such user directories even for users with a safe user name by submitting a crafted user name when attempting to log in, even with an invalid password. Doing so prevented users from logging in successfully afterwards.
References:
https://jenkins.io/security/advisory/2018-12-05/
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1656907]
Bugzilla
CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
bugzilla·2018-04-05·CVSS 6.5
CVE-2018-9133 [MEDIUM] CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
A flaw was found in ImageMagick 7.0.7-26 Q16. An excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
References:
https://github.com/ImageMagick/ImageMagick/issues/1072
Patch:
https://github.com/ImageMagick/ImageMagick/commit/089fca04e0130549fa15f48ace3f56e30a06049a
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180
Bugzilla
CVE-2018-1072 ovirt-engine-setup: unfiltered db password in engine-backup log
bugzilla·2018-03-09·CVSS 5.0
CVE-2018-1072 [MEDIUM] CVE-2018-1072 ovirt-engine-setup: unfiltered db password in engine-backup log
CVE-2018-1072 ovirt-engine-setup: unfiltered db password in engine-backup log
The ovirt-engine-provisiondb utility, which is called by engine-backup if invoked with one of the options --provision*db, logs the username and password of the db user without redaction.
Discussion:
Acknowledgments:
Name: Yedidyah Bar David (Red Hat)
---
External References:
https://bugzilla.redhat.com/show_bug.cgi?id=1540622
---
This issue has been addressed in the following products:
Red Hat Virtualization Engine 4.2
Via RHSA-2018:2071 https://access.redhat.com/errata/RHSA-2018:2071
2018-06-26
Published