Description of problem: 1. Go to Virtualization -> Templates (sources were auto-populated by setting default StorageClass) 2. Create new VM with Wizard 3. Select RHEL8 (or any other) 4. Next 5. Customize Virtual Machine 6. Click Advanced 7. Select Form View (default) 8. Type password under 'Password'. It's echoed back in the field in cleartext, please hide this. Version-Release number of selected component (if applicable): 4.10.9 How reproducible: Always Steps to Reproduce: As above. Actual results: * Password is shown cleartext in the browser Expected results: * Hide the password just typed Additional info: * This can potentially leak customer passwords in remote sessions (which are recorded), and other people can see cleartext passwords just by looking at the screen.
v4.11.0-403(OCP v4.11.0-32)
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Important: OpenShift Virtualization 4.11.0 Images security and bug fix update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2022:6526