Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7060

Опубликовано: 10 янв. 2017
Источник: redhat
CVSS3: 4.9
CVSS2: 4.7

Описание

The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.

It was found that several password fields in QCI failed to properly mask the password while it was being entered. An attacker with physical access or the ability to view the screen would be able to see the passwords as they are being entered, allowing them to later access accounts and services protected by those passwords.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1379909QCI: qci exposes password in web UI when they should be masked

4.9 Medium

CVSS3

4.7 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.6
nvd
почти 9 лет назад

The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.

CVSS3: 4.6
github
больше 3 лет назад

The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.

4.9 Medium

CVSS3

4.7 Medium

CVSS2