Business information leak In insights-core
Description
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component |
|---|---|
rpm rhel10 | |
rpm rhel10 | |
rpm rhel10 | |
rpm rhel9 |
Aliases
1. 2. 3.