Username and Password Stored in Clear Text in Red Hat Enterprise Virtualization 3.1
Issue
- According to Red Hat RHEVM documentation and backup instructions, /usr/share/ovirt-engine-reports/reports-INSERT_VERSION_NUMBER/users/rhevmreports/rhevm-002dadmin.xml contains plain-text, un-encrypted user and password information for the rhev-admin user.
- This violates many security policies that read similar to: "No system/user passwords shall be stored on any IT system in plain-text"
Environment
- Red Hat Enterprise Virtualization 3.1
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.