CVE-2022-2805
published 2022-10-19CVE-2022-2805: A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.40%
32.0th percentile
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r2ff-gw5r-6x3q: A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style
ghsa_unreviewed·2022-10-19
CVE-2022-2805 [MEDIUM] CWE-200 GHSA-r2ff-gw5r-6x3q: A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.
Red Hat
ovirt-engine: RHVM admin password is logged unfiltered when using otopi-style
vendor_redhat·2022-05-27·CVSS 6.5
CVE-2022-2805 [MEDIUM] CWE-312 ovirt-engine: RHVM admin password is logged unfiltered when using otopi-style
ovirt-engine: RHVM admin password is logged unfiltered when using otopi-style
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-19
Published