A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python-oslo-utils-langUpgrade python3-oslo-utils | Mar 25, 2022 | Mar 23, 2022 |
| Debian | — | Upgrade python-oslo.utils | Sep 15, 2022 | Aug 29, 2022 |
| Redhat_linux | — | Upgrade python-oslo-utils-langUpgrade python3-oslo-utils | Mar 25, 2022 | Mar 23, 2022 |
| Ubuntu | — | Upgrade python-oslo.utils (Ubuntu Pro)Upgrade python-oslo.utilsUpgrade python3-oslo.utils (Ubuntu Pro)Upgrade python3-oslo.utils | Apr 8, 2022 | Apr 7, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub