rhevm-log-collector not safe for all security credentials
Issue
rhevm-log-collector (from rhevm-log-collector-3.3.1-6.el6ev.noarch) gathers files that may leak secure credentials into the tarball
A brief review of what is being included in the rhevm-log-collector output, we've noticed:
- A database password could be sent here:
/etc/ovirt-engine/ovirt-engine-dwh/Default.properties - Initial passwords leaked here:
/var/lib/ovirt-engine/setup/answers/YYYYMMDDHHMMSS-setup.conf - In each of the per-hypervisor sosreports VDSM PKI private keys leaked:
/etc/vdsm/keys
Environment
Red Hat Enterprise Virtualization
3.3
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.