rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2013-02-24T22:00:00Z

Updated: 2024-08-06T21:14:16.412Z

Reserved: 2012-10-24T00:00:00Z

Link: CVE-2012-5658

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2013-02-24T22:55:01.033

Modified: 2013-02-26T05:00:00.000

Link: CVE-2012-5658

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-12-17T00:00:00Z

Links: CVE-2012-5658 - Bugzilla