It was found that ovirt-hosted-engine-setup did not correctly filter cloudInitRootPwd from the setup log file, exposing it in clear text where local users could potentially read it. Statement: Released versions of Red Hat Enterprise Virtualization were not impacted by this issue in practice as the passwords were not saved in the answerfile during provisioning.
Product bug, raised against RHV 4.2 beta: https://bugzilla.redhat.com/show_bug.cgi?id=1536941
External References: https://gerrit.ovirt.org/#/c/86635/ https://gerrit.ovirt.org/#/c/62679/