CVE Vulnerabilities

CVE-2016-5411

Published: Jun 13, 2017 | Modified: Jul 05, 2017
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
4.9 MODERATE
AV:L/AC:L/Au:N/C:C/I:N/A:N
RedHat/V3
7.1 MODERATE
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Ubuntu

/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.

Affected Software

Name Vendor Start Version End Version
Quickstart_cloud_installer Redhat 0.9 (including) 0.9 (including)

References