CVE-2018-1000018: Ovirt Ovirt-Hosted-Engine-Setup
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
Affected products
- Ovirt Ovirt-Hosted-Engine-Setup: before 2.2.7 (fixed in 2.2.7)
Published 2018-01-24. Last modified 2026-06-17.