-
Bug
-
Resolution: Done-Errata
-
None
-
Quality / Stability / Reliability
-
False
-
-
False
-
CLOSED
-
Moderate
-
No
Description of problem:
1. Go to Virtualization -> Templates (sources were auto-populated by setting default StorageClass)
2. Create new VM with Wizard
3. Select RHEL8 (or any other)
4. Next
5. Customize Virtual Machine
6. Click Advanced
7. Select Form View (default)
8. Type password under 'Password'.
It's echoed back in the field in cleartext, please hide this.
Version-Release number of selected component (if applicable):
4.10.9
How reproducible:
Always
Steps to Reproduce:
As above.
Actual results:
- Password is shown cleartext in the browser
Expected results:
- Hide the password just typed
Additional info:
- This can potentially leak customer passwords in remote sessions (which are recorded), and other people can see cleartext passwords just by looking at the screen.