LOW
GHSA-rxrm-xvp4-jqvh
OpenStack Keystone Sensitive information disclosure via log files
Details
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-2006 [ADVISORY]
- https://github.com/openstack/keystone/commit/c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd [WEB]
- https://github.com/openstack/keystone/commit/d43e2a51a1ed7adbed3c5ddf001d46bc4a824ae8 [WEB]
- https://bugs.launchpad.net/keystone/+bug/1172195 [WEB]
- https://bugs.launchpad.net/ossn/+bug/1168252 [WEB]
- https://github.com/openstack/keystone [PACKAGE]
- https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2013-40.yaml [WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105916.html [WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106220.html [WEB]
- http://rhn.redhat.com/errata/RHSA-2013-0806.html [WEB]
- http://www.openwall.com/lists/oss-security/2013/04/24/1 [WEB]
- http://www.openwall.com/lists/oss-security/2013/04/24/2 [WEB]
- http://www.securityfocus.com/bid/59411 [WEB]