A vulnerability was discovered in virutalbmc impacting rhosp 13. If a user configured a VNC console for a virtual machine under virtualbmc's power/boot device management, the password could be stripped from the libvirt virtual machine domain. * Upstream Storyboard: https://storyboard.openstack.org/#!/story/2010382 * Downstream BZ: https://bugzilla.redhat.com/show_bug.cgi?id=2137679 * Impacted package: https://brewweb.engineering.redhat.com/brew/packageinfo?packageID=61530 * Impacted RPM for RHOSP13 https://brewweb.engineering.redhat.com/brew/buildinfo?buildID=666478
Lifting eternal embargo and closing as duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=2137679 which has been public from the start