CVE-2022-2805 PUBLISHED CVSS 6.5 MEDIUM

A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.

EPSS 0.11% · 29.5th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.11%
29.5th percentile

Affected Products

VendorProductVersions
redhatvirtualization4.0
n/aovirt-engineovirt-engine 4.5.3

Timeline

References

Open in Interactive Console →