Sos Project Sos vulnerabilities
3 known vulnerabilities affecting sos_project/sos.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2022-2806MEDIUMCVSS 5.5fixed in 4.2-20.el8_62022-09-01
CVE-2022-2806 [MEDIUM] CWE-200 CVE-2022-2806: It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixe
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
nvd
CVE-2015-7529HIGHCVSS 7.8≥ 3.0, ≤ 3.82017-11-06
CVE-2015-7529 [HIGH] CWE-59 CVE-2015-7529: sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
nvd
CVE-2015-3171MEDIUMCVSS 5.5v3.22017-07-25
CVE-2015-3171 [MEDIUM] CWE-200 CVE-2015-3171: sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.
nvd