The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1379909 | Issue Tracking Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2017:0256 | |
http://www.securityfocus.com/bid/97678 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-04-14 11:59
Updated : 2017-04-24 17:39
NVD link : CVE-2016-7060
Mitre link : CVE-2016-7060
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
redhat
- quickstart_cloud_installer