RHSA-2018:1452LowCVSS 5.0

Red Hat Security Advisory: ovirt-ansible-roles security update

Published
May 15, 2018
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2018-1117 — no_log directive: passwords revealed in ansible log when provisioning new provider

🎯 Affected products3

  • Red Hat Virtualization Manager 4.1
  • ovirt-ansible-roles-0:1.0.6-1.el7ev.noarch as a component of Red Hat Virtualization Manager 4.1
  • ovirt-ansible-roles-0:1.0.6-1.el7ev.src as a component of Red Hat Virtualization Manager 4.1

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate the risk of administrative password disclosure, ensure that system logs, particularly those generated during oVirt provider provisioning, are protected with strict access controls. Limit access to these logs to authorized personnel only and avoid sharing them with untrusted systems or users.

🔗 References (4)