Red Hat Bugzilla – Bug 228637
CVE-2007-1462 security alert - passwords sent back from server as input value
Last modified: 2009-04-16 18:42:59 EDT
The password for the remote system(s) is persisted between two page loads in the Add System/Cluster task flow. If it were persisted in the server session it would not be a problem, but instead it it is returned to the browser as a 'Value' attribute in a password entry field widget. This means that if the user were to 'View Source', the password would appear as plaintext in the html. NOTE: All luci interaction is done via HTTPS; still this does present a remote, but possible means of exploit.
Created attachment 148037 [details] copy of letter sent to security response team
This is an issue that would require quite unlikely circumstances to exploit (user walks away, works offline) and is mitigated from a man-in-the-middle by SSL, so I'd rate this as having low security impact. http://www.redhat.com/security/updates/classification/
Ack for 5.1 train.
Fixing Product name.
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2007-0331.html