In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
{ "cpe": "cpe:2.3:a:redhat:ovirt-engine:4.1.0:-:*:*:*:*:*:*", "extracted_events": [ { "introduced": "4.1.0-NA" }, { "last_affected": "4.1.0-NA" } ], "source": "CPE_STRING" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7510.json"