oVirt Engine CVE-2017-15113 Debug Logging Information Disclosure Vulnerability
BID:101933
CVE-2017-15113 |Info
oVirt Engine CVE-2017-15113 Debug Logging Information Disclosure Vulnerability
| Bugtraq ID: | 101933 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-15113 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 13 2017 12:00AM |
| Updated: | Dec 19 2017 10:00PM |
| Credit: | Jiri Belka |
| Vulnerable: |
Redhat RHEV-M for Servers 0 Redhat RHEV-M 4.0 oVirt Engine 4.1.7 oVirt Engine 4.0.3 oVirt Engine 4.0.2 oVirt Engine 4.0.1 oVirt Engine 4.0 |
| Not Vulnerable: |
oVirt Engine 4.1.7.6-0.1 |
Discussion
oVirt Engine CVE-2017-15113 Debug Logging Information Disclosure Vulnerability
oVirt Engine is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information. Successful exploits may lead to other attacks.
oVirt Engine is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information. Successful exploits may lead to other attacks.
Exploit / POC
oVirt Engine CVE-2017-15113 Debug Logging Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
oVirt Engine CVE-2017-15113 Debug Logging Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
oVirt Engine CVE-2017-15113 Debug Logging Information Disclosure Vulnerability
References:
References:
- CVE-2017-15113 (redhat)
- DEBUG info (bugzilla)
- RHEA-2017:3138 - Product Enhancement Advisory (Red Hat)