MEDIUM5.5
PYSEC-2026-1405
glance-store logs s3 access keys
Quick fix
PYSEC-2026-1405 — glance-store: upgrade to the fixed version with the command below.
pip install --upgrade 'glance-store>=4.7.0'Details
A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-1141[ADVISORY]
- https://github.com/openstack/glance_store/commit/d6e531af4821c8466b1e9404f12f89f6216417f2[FIX]
- https://access.redhat.com/errata/RHSA-2024:2732[WEB]
- https://access.redhat.com/security/cve/CVE-2024-1141[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2258836[WEB]
- https://github.com/openstack/glance_store[PACKAGE]
- https://pypi.org/project/glance-store[PACKAGE]
- https://github.com/advisories/GHSA-wgpq-p2hm-56v9[ADVISORY]