CVE-2022-2806 is a vulnerability in ovirt-log-collector and sosreport that causes the unfiltered collection of the RHV admin password. This affects ovirt log_collector, ovirt sos, and sos_project log_collector and sos. Rated as MEDIUM severity (CVSS 5.5), it has a local attack vector with low complexity, allowing an authenticated attacker to achieve high confidentiality impact by accessing sensitive information. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2-20.el8_6CPE matchmatch criteria | cpe:2.3:a:sos_project:sos:*:*:*:*:*:*:*:* | ||
< 4.4.7-2.el8evCPE matchmatch criteria | cpe:2.3:a:ovirt:log_collector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6 ovirt-log-collector-4.4.7-2.el8ev
Sep 13, 2022sosreport Exposure of Sensitive Information vulnerability
Sep 2, 2022ovirt-log-collector: RHVM admin password is logged unfiltered
May 27, 2022