Back to bug 1379909

Who When What Removed Added
Kurt Seifried 2016-09-28 04:18:13 UTC CC security-response-team
Kurt Seifried 2016-09-28 04:21:05 UTC Blocks 1379910
Kurt Seifried 2016-09-28 04:24:14 UTC CC jmatthew
Kurt Seifried 2016-11-02 01:40:16 UTC Depends On 1390813
Thom Carlin 2016-11-15 16:53:12 UTC CC cchase
Jesus M. Rodriguez 2016-11-19 15:57:39 UTC Status NEW MODIFIED
Status MODIFIED NEW
CC jesusr
Depends On 1396744
Jesus M. Rodriguez 2016-11-21 16:12:42 UTC Status NEW MODIFIED
Kurt Seifried 2017-01-10 16:38:45 UTC Whiteboard impact=moderate,public=no,reported=20160910,source=redhat,cvss2=4.7/AV:L/AC:M/Au:N/C:C/I:N/A:N,cvss3=4.9/CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N,cwe=CWE-200,qci-1/Distribution=affected impact=moderate,public=20170110,reported=20160910,source=redhat,cvss2=4.7/AV:L/AC:M/Au:N/C:C/I:N/A:N,cvss3=4.9/CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N,cwe=CWE-200,qci-1/Distribution=affected
Kurt Seifried 2017-01-10 16:38:50 UTC Summary EMBARGOED CVE-2016-7060 Red Hat QCI: qci exposes password in web UI when they should be masked CVE-2016-7060 Red Hat QCI: qci exposes password in web UI when they should be masked
Kurt Seifried 2017-01-10 16:38:55 UTC Group security, qe_staff
Kurt Seifried 2017-01-12 20:24:12 UTC Doc Text It was found that several password fields in QCI filed to properly mask the password while it was being entered. An attacker with physical access or the ability to view the screen would be able to see the passwords as they are being entered, allowing them to later access accounts and services protected by those passwords.
Eric Christensen 2017-01-12 21:27:14 UTC Doc Text It was found that several password fields in QCI filed to properly mask the password while it was being entered. An attacker with physical access or the ability to view the screen would be able to see the passwords as they are being entered, allowing them to later access accounts and services protected by those passwords. It was found that several password fields in QCI failed to properly mask the password while it was being entered. An attacker with physical access or the ability to view the screen would be able to see the passwords as they are being entered, allowing them to later access accounts and services protected by those passwords.
Kurt Seifried 2017-03-06 19:51:03 UTC Status MODIFIED CLOSED
Resolution --- ERRATA
Last Closed 2017-03-06 14:51:03 UTC
Product Security DevOps Team 2019-09-29 13:57:05 UTC Whiteboard impact=moderate,public=20170110,reported=20160910,source=redhat,cvss2=4.7/AV:L/AC:M/Au:N/C:C/I:N/A:N,cvss3=4.9/CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N,cwe=CWE-200,qci-1/Distribution=affected

Back to bug 1379909