ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ovirt | Ovirt | * | 4.1.11.1 (including) |
Red Hat Virtualization Engine 4.1 | RedHat | org.ovirt.engine-root-0:4.1.11.2-1 | * |