Vulnerabilities > Ovirt > Ovirt > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-07-11 CVE-2019-10194 Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions.
local
low complexity
ovirt redhat
5.5
2018-07-27 CVE-2017-15113 Information Exposure Through Log Files vulnerability in multiple products
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking.
network
high complexity
ovirt redhat CWE-532
6.6
2017-04-20 CVE-2016-6341 Information Exposure vulnerability in Ovirt
oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.
local
low complexity
ovirt CWE-200
5.5