CVE-2018-1073
published 2018-06-19CVE-2018-1073: The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to…
medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | ovirt-engine | < 4.2.3 | 4.2.3 |
| redhat | virtualization | — | — |
| redhat | virtualization_host | — | — |