RHSA-2018:1452LowCVSS 5.0
Red Hat Security Advisory: ovirt-ansible-roles security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2018-1117 — no_log directive: passwords revealed in ansible log when provisioning new provider
🎯 Affected products3
- Red Hat Virtualization Manager 4.1
- ovirt-ansible-roles-0:1.0.6-1.el7ev.noarch as a component of Red Hat Virtualization Manager 4.1
- ovirt-ansible-roles-0:1.0.6-1.el7ev.src as a component of Red Hat Virtualization Manager 4.1
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate the risk of administrative password disclosure, ensure that system logs, particularly those generated during oVirt provider provisioning, are protected with strict access controls. Limit access to these logs to authorized personnel only and avoid sharing them with untrusted systems or users.