PYSEC-2013-40
Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.
Quick fix
PYSEC-2013-40 — keystone: upgrade to the fixed version with the command below.
pip install --upgrade 'keystone>=c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd'Details
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/keystone
Introduced in:
0Fixed in: c5037dd6b82909efaaa8720e8cfa8bdb8b4a0eddFix
pip install --upgrade 'keystone>=c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd'References
- https://bugs.launchpad.net/ossn/+bug/1168252[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-0806.html[ADVISORY]
- http://www.openwall.com/lists/oss-security/2013/04/24/1[WEB]
- https://bugs.launchpad.net/keystone/+bug/1172195[WEB]
- http://www.securityfocus.com/bid/59411[WEB]
- http://www.openwall.com/lists/oss-security/2013/04/24/2[WEB]
- https://github.com/openstack/keystone/commit/c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd[FIX]
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106220.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105916.html[WEB]
- https://github.com/advisories/GHSA-rxrm-xvp4-jqvh[ADVISORY]