A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 07:17
Updated : 2026-08-14 19:07
NVD link : CVE-2026-19391
Mitre link : CVE-2026-19391
CVE.ORG link : CVE-2026-19391
JSON object : View
Products Affected
No product.
CWE
CWE-312
Cleartext Storage of Sensitive Information
