Red Hat Bugzilla – Bug 1366412
CVE-2016-5411 QCI: creates world readable /var/lib/ovirt-engine/setup/engine-DC-config.py contains sensitive password
Last modified: 2016-09-30 15:32:20 EDT
Thom Carlin of Red Hat report: The file /var/lib/ovirt-engine/setup/engine-DC-config.py is created world readable and contains the root password for the deployed system.
Acknowledgments: Name: Thom Carlin (Red Hat)
This was fixed in QCI 1.0 GA.