CyberRota Analysis
AI-GeneratedA vulnerability exists in the insights-core component, where the password redaction mechanism inadequately identifies credentials not explicitly labeled as 'password'. This oversight permits sensitive SSSD LDAP bind passwords and Pacemaker fence device credentials to be exposed in cleartext within archives sent to console.redhat.com. Organizations utilizing insights-core should prioritize addressing this flaw to mitigate the risk of credential leakage.
Original NVD Description
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.