Project

General

Profile

Actions

Bug #15517

closed

Root password is sent to system journal in clear text when set

Added by Lukas Zapletal over 8 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Normal
Category:
Image
Target version:
Difficulty:
trivial
Triaged:
Fixed in Releases:
Found in Releases:

Description

By default root account is locked on discovered nodes, user needs to enable ssh service manually and enter root password in the dialog. Then it makes into the system journal in clear text.

This is being tracked as CVE-2016-4996, moderate impact.

Acknowledgments:

Name: Thom Carlin (Red Hat)

Actions

Also available in: Atom PDF