PT-2017-9082 · Red Hat · Red Hat Quickstart Cloud Installer
Kurt Seifried
·
Publicado
2017-04-14
·
Atualizado
2017-04-25
·
CVE-2016-7060
CVSS v3.1
4.6
Média
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat QuickStart Cloud Installer (QCI) version 1.0
Description
The issue concerns the web interface of the affected software, where password fields are not masked. This allows physically proximate attackers to obtain sensitive password information by reading the display.
Recommendations
For Red Hat QuickStart Cloud Installer (QCI) version 1.0, consider implementing password masking in the web interface to prevent unauthorized access to sensitive information.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Quickstart Cloud Installer