Vulnerabilities > Ovirt > Cockpit Ovirt

DATE CVE VULNERABILITY TITLE RISK
2019-05-17 CVE-2019-10139 Insufficiently Protected Credentials vulnerability in Ovirt Cockpit-Ovirt
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text.
local
low complexity
ovirt CWE-522
7.8