A password leak was identified on Red Hat Satellite which will expose BMC password in plaintext through the compute host API.
Acknowledgments: Name: Evgeni Golov (Red Hat)
Statement: Red Hat Satellite is vulnerable to the BMC controller credential leak through the compute host API. Red Hat Product Security has rated this flaw as having a security impact of Moderate. Please refer to https://access.redhat.com/security/updates/classification for clarification on the scoring.
This issue has been addressed in the following products: Red Hat Satellite 6.10 for RHEL 7 Via RHSA-2021:4702 https://access.redhat.com/errata/RHSA-2021:4702