Actions
Bug #15517
closedRoot password is sent to system journal in clear text when set
Status:
Closed
Priority:
Normal
Assignee:
Category:
Image
Target version:
Difficulty:
trivial
Triaged:
Bugzilla link:
Description
By default root account is locked on discovered nodes, user needs to enable ssh service manually and enter root password in the dialog. Then it makes into the system journal in clear text.
This is being tracked as CVE-2016-4996, moderate impact.
Acknowledgments:
Name: Thom Carlin (Red Hat)
Actions