Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-4579

vmware upload mangles URL and exposes passwords in /var/log/messages

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • rhel-9.0.0
    • cockpit-composer
    • None
    • Moderate
    • sst_image_builder
    • ssg_front_door
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None

      Description of problem:
      RHEL 9 building images using cockpit-composer and uploading to vmware, image generation succeeds, but upload of image fails. URL for target is not what is expected and plain text password is exposed in /var/log/messages

      Version-Release number of selected component (if applicable):
      9.0

      How reproducible:
      always

      Steps to Reproduce:
      1. Create a blueprint
      2. Create image selecting vmdk
      3. Select upload to vmware
      4. Set authentication and destination
      authentication:
      username: administrator@vsphere.local (non-AD integrated vcenter appliance)
      password: MyPassword
      destination:
      Image name: devbox
      Host: vcenter.parmstrong.ca
      Cluster: NUCLab
      Data center: parmstrong.ca
      Data store: SYN_VMS

      Actual results:
      Jun 29 16:08:27 imagebuilder9 osbuild-worker[41364]: /usr/libexec/osbuild-composer/osbuild-worker: Post "https://administrator/sdkMyPassword@vcenter.parmstrong.ca": dial tcp: lookup administrator on 192.168.252.10:53: no such host
      Jun 29 16:08:27 imagebuilder9 osbuild-worker[41364]: time="2022-06-29T16:08:27-04:00" level=error msg="osbuild job failed: importing vmdk failed" jobId=95888748-9ab1-435d-ae68-76c2bc19d2e6
      Jun 29 16:08:27 imagebuilder9 osbuild-worker[41364]: time="2022-06-29T16:08:27-04:00" level=info msg="Job '95888748-9ab1-435d-ae68-76c2bc19d2e6' (osbuild) finished"

      Expected results:
      Upload succeeds
      passwords are NOT exposed!!

      Additional info:
      osbuild-53.1-1.el9_0.noarch
      cockpit-composer-36-1.el9_0.noarch
      osbuild-composer-46.3-1.el9_0.x86_64

            obudai@redhat.com Ondrej Budai
            parmstro@redhat.com Paul Armstrong
            Ondrej Budai Ondrej Budai
            RH Bugzilla Integration RH Bugzilla Integration
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: