CVE-2022-0207
published 2022-08-26CVE-2022-0207: A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
PriorityP420medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.19%
8.4th percentile
A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt | vdsm | — | — |
| ovirt | vdsm | >= 4.30.1 < 4.50.0.4 | 4.50.0.4 |
| redhat | virtualization | — | — |
| redhat | virtualization_for_ibm_power_little_endian | — | — |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
vdsm: disclosure of sensitive values in log files
vendor_redhat·2022-01-11·CVSS 4.7
CVE-2022-0207 [MEDIUM] CWE-362 vdsm: disclosure of sensitive values in log files
vdsm: disclosure of sensitive values in log files
A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
GHSA
GHSA-32qr-rh8p-qfq7: A race condition was found in vdsm
ghsa_unreviewed·2022-08-27
CVE-2022-0207 [MEDIUM] CWE-362 GHSA-32qr-rh8p-qfq7: A race condition was found in vdsm
A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-0207https://bugzilla.redhat.com/show_bug.cgi?id=2033697https://bugzilla.redhat.com/show_bug.cgi?id=2039248https://gerrit.ovirt.org/c/vdsm/+/118025https://gerrit.ovirt.org/gitweb?p=vdsm.git%3Ba=commit%3Bh=53b0036fc72d3b8877d4e7f047d705e5a4c722e8https://access.redhat.com/security/cve/CVE-2022-0207https://bugzilla.redhat.com/show_bug.cgi?id=2033697https://bugzilla.redhat.com/show_bug.cgi?id=2039248https://gerrit.ovirt.org/c/vdsm/+/118025https://gerrit.ovirt.org/gitweb?p=vdsm.git%3Ba=commit%3Bh=53b0036fc72d3b8877d4e7f047d705e5a4c722e8
2022-08-26
Published