VDB
EN
MEDIUM

GHSA-xv7j-2v4w-cjvh

OpenStack Glance logs user name and password in cleartext

상세

store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / glance
최초 영향 버전: 2012.1 수정 버전: 2012.2.3
수정 pip install --upgrade 'glance>=2012.2.3'

참고