A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | centos-upgrade-python-oslo-utils-langcentos-upgrade-python3-oslo-utils | Mar 25, 2022 | Mar 23, 2022 |
| Debian | debian-upgrade-python-oslo-utils | Sep 15, 2022 | Aug 29, 2022 | |
| Redhat_linux | — | redhat-upgrade-python-oslo-utils-langredhat-upgrade-python3-oslo-utils | Mar 25, 2022 | Mar 23, 2022 |
| Ubuntu | ubuntu-pro-upgrade-python-oslo-utilsubuntu-pro-upgrade-python3-oslo-utilsubuntu-upgrade-python-oslo-utilsubuntu-upgrade-python3-oslo-utils | Apr 8, 2022 | Apr 7, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub