Description
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4448 | OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs. |
Github GHSA |
GHSA-jwpw-ppj5-7h4w | OpenStack Keystone Logs Passwords |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T05:47:58.237Z
Reserved: 2015-05-04T00:00:00.000Z
Link: CVE-2015-3646
No data.
Status : Deferred
Published: 2015-05-12T19:59:26.263
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-3646
OpenCVE Enrichment
No data.
EUVD
Github GHSA