SB2022092637 - Ubuntu update for sosreport
Published: September 26, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2022-2806)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to gain access to sensitive information.
The
vulnerability exists due to the application does not apply encryption
or obfuscation for the RHV admin password. An attacker with access to
the application can gain access to sensitive information.
Remediation
Install update from vendor's website.