CVE-2019-10139: Ovirt Cockpit-Ovirt

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.

Affected products

  • Ovirt Cockpit-Ovirt: affected versions not specified

Published 2019-05-17. Last modified 2026-06-17.