The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/97678 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2017:0256 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1379909 | Issue Tracking Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2017-04-14 18:59
Updated : 2024-02-04 19:11
NVD link : CVE-2016-7060
Mitre link : CVE-2016-7060
CVE.ORG link : CVE-2016-7060
JSON object : View
Products Affected
redhat
- quickstart_cloud_installer
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor