Loading HuntDB...

GHSA-9fw7-mcq9-ghf3

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

Related CVEs

Key Information

GHSA ID
GHSA-9fw7-mcq9-ghf3
Published
May 13, 2022 1:33 AM
Last Modified
May 13, 2022 1:33 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.