CVE-2016-5411: Red Hat Quickstart Cloud Installer

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.

Affected products

  • Red Hat Quickstart Cloud Installer: version 0.9 only

Published 2017-06-13. Last modified 2026-06-17.