CVE-2018-1074
published 2018-04-26CVE-2018-1074: ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including…
PriorityP340high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
1.50%
71.3th percentile
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | ovirt | <= 4.1.11.1 | — |
| redhat | enterprise_virtualization | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qmxf-r2wh-hqpc: ovirt-engine API and administration web portal before versions 4
ghsa_unreviewed·2022-05-13
CVE-2018-1074 [HIGH] CWE-522 GHSA-qmxf-r2wh-hqpc: ovirt-engine API and administration web portal before versions 4
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
Red Hat
ovirt-engine: API exposes power management credentials to administrators
vendor_redhat·2018-04-26·CVSS 7.7
CVE-2018-1074 [HIGH] CWE-200 ovirt-engine: API exposes power management credentials to administrators
ovirt-engine: API exposes power management credentials to administrators
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
The ovirt-engine API and administration web portal exposed Power Management credentials including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
Package: ovirt-engine (Red Hat Enterprise Virtualization 3) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000406 jenkins: Arbitrary file write vulnerability using file parameter definitions
bugzilla·2018-10-25·CVSS 6.5
CVE-2018-1000406 [MEDIUM] CVE-2018-1000406 jenkins: Arbitrary file write vulnerability using file parameter definitions
CVE-2018-1000406 jenkins: Arbitrary file write vulnerability using file parameter definitions
Users with Job/Configure permission could specify a relative path escaping the base directory in the file name portion of a file parameter definition. This path would be used to archive the uploaded file on the Jenkins master, resulting in an arbitrary file write vulnerability.
External References:
https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1074
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1642894]
---
Jenkins security policy[0]:
"Any security advisory related updates to Jenkins core or the plugins we include in the OpenShift Jenkins master image will only occur in the v3.11 and v4.x branches of this repository.
We do support running t
Bugzilla
CVE-2018-1074 ovirt-engine: API exposes power management credentials to administrators
bugzilla·2018-03-09·CVSS 7.7
CVE-2018-1074 [HIGH] CVE-2018-1074 ovirt-engine: API exposes power management credentials to administrators
CVE-2018-1074 ovirt-engine: API exposes power management credentials to administrators
The ovirt-engine API and administration web portal exposed Power Management credentials including cleartext passwords to Host Administrators.
Discussion:
Doran, which version is affected by this bug? Has this issue been already fixed?
This bug has no useful information for addressing the issue.
Is the issue handled in bug #1553207 ? I have no access to it.
---
This issue was addressed in Red Hat Virtualization Manager (ovirt-engine) 4.1.11 via:
https://access.redhat.com/errata/RHBA-2018:1219
2018-04-26
Published