What the vulnerability does

01Description

In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.

Key dates

02Disclosure timeline

March 25, 2019 CVE published
August 5, 2024 Record updated