CVE-2016-7060: Infoleak
The QCI QE Team of Red Hat reports:
In multiple locations within the web interface for QCI the password is shown by default when it should be masked by default.
Other sources
The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7060?
CVE-2016-7060 is classified as a moderate severity vulnerability.
How do I fix CVE-2016-7060?
To fix CVE-2016-7060, ensure that password fields in the QCI web interface are configured to mask the passwords by default.
Who is affected by CVE-2016-7060?
CVE-2016-7060 affects users of Red Hat QuickStart Cloud Installer version 1.0.
What impacts does CVE-2016-7060 have?
CVE-2016-7060 can lead to unauthorized access as passwords are visible to anyone physically present near the interface.
Is there a workaround for CVE-2016-7060?
Currently, there are no documented workarounds for CVE-2016-7060; the best practice is to apply the patch provided by Red Hat.