CVE-2022-2806
ovirt-log-collector: RHVM admin password is logged unfiltered
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
Se ha detectado que ovirt-log-collector/sosreport recoge la contraseƱa de administrador de RHV sin filtrar. Corregido en: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
A flaw was found in the ovirt-log-collector, which led to the logging of plaintext passwords in the log file. This flaw allows an attacker with sufficient privileges to read the log file, leading to a loss of confidentiality.
The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning. Issues addressed include code execution, cross site scripting, and denial of service vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-08-12 CVE Reserved
- 2022-09-01 CVE Published
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/sosreport/sos/pull/2947 | 2022-09-07 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-2806 | 2022-09-08 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2080005 | 2022-09-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sos Project Search vendor "Sos Project" | Sos Search vendor "Sos Project" for product "Sos" | < 4.2-20.el8_6 Search vendor "Sos Project" for product "Sos" and version " < 4.2-20.el8_6" | - |
Affected
| ||||||
Ovirt Search vendor "Ovirt" | Log Collector Search vendor "Ovirt" for product "Log Collector" | < 4.4.7-2.el8ev Search vendor "Ovirt" for product "Log Collector" and version " < 4.4.7-2.el8ev" | - |
Affected
|