CVE-2018-1073
published 2018-06-19CVE-2018-1073: The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.91%
77.4th percentile
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | ovirt-engine | < 4.2.3 | 4.2.3 |
| redhat | virtualization | — | — |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ovirt-engine: account enumeration through login to web console
vendor_redhat·2018-05-15·CVSS 5.3
CVE-2018-1073 [MEDIUM] CWE-209 ovirt-engine: account enumeration through login to web console
ovirt-engine: account enumeration through login to web console
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
The ovirt-engine web console login form returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
GHSA
GHSA-9ghh-fm37-vrf7: The web console login form in ovirt-engine before version 4
ghsa_unreviewed·2022-05-13
CVE-2018-1073 [MEDIUM] CWE-200 GHSA-9ghh-fm37-vrf7: The web console login form in ovirt-engine before version 4
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20145 mosquitto: Possible ACL bypass
bugzilla·2018-12-18·CVSS 7.5
CVE-2018-20145 [HIGH] CVE-2018-20145 mosquitto: Possible ACL bypass
CVE-2018-20145 mosquitto: Possible ACL bypass
Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.
Upstream issue:
https://github.com/eclipse/mosquitto/issues/1073
Upstream patch:
https://github.com/eclipse/mosquitto/commit/9097577b49b7fdcf45d30975976dd93808ccc0c4
Discussion:
Created mosquitto tracking bugs for this issue:
Affects: epel-7 [bug 1660415]
Affects: fedora-all [bug 1660414]
Bugzilla
CVE-2018-1073 ovirt-engine: account enumeration through login to web console
bugzilla·2018-03-09·CVSS 5.3
CVE-2018-1073 [MEDIUM] CVE-2018-1073 ovirt-engine: account enumeration through login to web console
CVE-2018-1073 ovirt-engine: account enumeration through login to web console
The web console login form returned two different errors for non-existent users and invalid password attempts, allowing an attacker to discover the names of valid user accounts.
Discussion:
This issue has been addressed in the following products:
Red Hat Virtualization 4 for RHEL-7
Via RHSA-2018:1525 https://access.redhat.com/errata/RHSA-2018:1525
2018-06-19
Published