Bug 1379909 (CVE-2016-7060) - CVE-2016-7060 Red Hat QCI: qci exposes password in web UI when they should be masked
Summary: CVE-2016-7060 Red Hat QCI: qci exposes password in web UI when they should be...
Alias: CVE-2016-7060
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1390813 1396744
Blocks: 1379910
TreeView+ depends on / blocked
Reported: 2016-09-28 04:18 UTC by Kurt Seifried
Modified: 2021-02-17 03:15 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
It was found that several password fields in QCI failed to properly mask the password while it was being entered. An attacker with physical access or the ability to view the screen would be able to see the passwords as they are being entered, allowing them to later access accounts and services protected by those passwords.
Clone Of:
Last Closed: 2017-03-06 19:51:03 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:0256 0 normal SHIPPED_LIVE Moderate: tfm-rubygem-fusor_ui security update 2017-02-07 01:27:34 UTC

Description Kurt Seifried 2016-09-28 04:18:13 UTC
The QCI QE Team of Red Hat reports:

In multiple locations within the web interface for QCI the password is shown 
by default when it should be masked by default.

Comment 1 Kurt Seifried 2016-09-28 04:18:19 UTC

Name: QCI QE Team (Red Hat)

Comment 4 errata-xmlrpc 2017-02-06 20:27:52 UTC
This issue has been addressed in the following products:

  QCI 1.0

Via RHSA-2017:0256 https://access.redhat.com/errata/RHSA-2017:0256

Note You need to log in before you can comment on or make changes to this bug.