The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/bid/97678 | Third Party Advisory VDB Entry | 
| https://access.redhat.com/errata/RHSA-2017:0256 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1379909 | Issue Tracking Third Party Advisory VDB Entry | 
| http://www.securityfocus.com/bid/97678 | Third Party Advisory VDB Entry | 
| https://access.redhat.com/errata/RHSA-2017:0256 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1379909 | Issue Tracking Third Party Advisory VDB Entry | 
Configurations
                    History
                    21 Nov 2024, 02:57
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.securityfocus.com/bid/97678 - Third Party Advisory, VDB Entry | |
| References | () https://access.redhat.com/errata/RHSA-2017:0256 - | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=1379909 - Issue Tracking, Third Party Advisory, VDB Entry | 
Information
                Published : 2017-04-14 18:59
Updated : 2025-04-20 01:37
NVD link : CVE-2016-7060
Mitre link : CVE-2016-7060
CVE.ORG link : CVE-2016-7060
JSON object : View
Products Affected
                redhat
- quickstart_cloud_installer
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
