Uploaded image for project: 'OpenShift Virtualization'
  1. OpenShift Virtualization
  2. CNV-17892

[2078703] [RFE] Please hide the user defined password when customizing cloud-init

XMLWordPrintable

    • Moderate
    • No

      Description of problem:

      1. Go to Virtualization -> Templates (sources were auto-populated by setting default StorageClass)
      2. Create new VM with Wizard
      3. Select RHEL8 (or any other)
      4. Next
      5. Customize Virtual Machine
      6. Click Advanced
      7. Select Form View (default)
      8. Type password under 'Password'.

      It's echoed back in the field in cleartext, please hide this.

      Version-Release number of selected component (if applicable):
      4.10.9

      How reproducible:
      Always

      Steps to Reproduce:
      As above.

      Actual results:

      • Password is shown cleartext in the browser

      Expected results:

      • Hide the password just typed

      Additional info:

      • This can potentially leak customer passwords in remote sessions (which are recorded), and other people can see cleartext passwords just by looking at the screen.

              mschatzm@redhat.com Matan Schatzman
              rhn-support-gveitmic Germano Veit Michel
              Guohua Ouyang Guohua Ouyang
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: