cbcvebase.
CVE-2018-1073
published 2018-06-19

CVE-2018-1073: The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.

Affected

3 ranges
VendorProductVersion rangeFixed in
ovirtovirt-engine< 4.2.34.2.3
redhatvirtualization
redhatvirtualization_host