CVE-2018-1074

Impact:
Low
Public Date:
2018-04-26
CWE:
CWE-200
Bugzilla:
1553529: CVE-2018-1074 ovirt-engine: API exposes power management credentials to administrators
The ovirt-engine API and administration web portal exposed Power Management credentials including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.

Find out more about CVE-2018-1074 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 7.7
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality High
Integrity Impact None
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Virtualization 4 (org.ovirt.engine-root) RHBA-2018:1219 2018-04-24

Affected Packages State

Platform Package State
Red Hat Virtualization 4 ovirt-engine Affected
RHEV Manager 3 ovirt-engine Will not fix

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.