The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
https://bugzilla.redhat.com/show_bug.cgi?id=1379909
http://www.securityfocus.com/bid/97678
https://access.redhat.com/errata/RHSA-2017:0256
Source: Mitre, NVD
Published: 2017-04-14
Updated: 2026-06-17
Base Score: 2.1
Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N
Severity: Low
Base Score: 4.6
Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: Medium
EPSS: 0.0008