VulnerabilityModified
CVE-2019-10194
Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.
MEDIUM 5.5EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- ovirt/ovirt · redhat/virtualization manager
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/109140Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2499Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10194Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/109140Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2499Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10194Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.