During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.
References
Link Resource
http://www.securityfocus.com/bid/108396 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2019:2433 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2437 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10139 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2019-05-17T15:28:59

Updated: 2019-08-12T13:06:16

Reserved: 2019-03-27T00:00:00


Link: CVE-2019-10139

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-05-17T16:29:03.017

Modified: 2023-02-12T23:32:55.177


Link: CVE-2019-10139

JSON object: View

cve-icon Redhat Information

No data.