A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1748185 | issue tracking exploit vendor advisory |
https://access.redhat.com/security/cve/CVE-2019-14840 | vendor advisory |