Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xw6-hj5p-4j79

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 6.2

Описание

OpenStack Glance sensitive information disclosure via logs

OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.

Пакеты

Наименование

glance

pip
Затронутые версииВерсия исправления

< 11.0.0a0

11.0.0a0

EPSS

Процентиль: 19%
0.00062
Низкий

5.1 Medium

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

ubuntu
почти 12 лет назад

OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.

redhat
почти 12 лет назад

OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.

nvd
почти 12 лет назад

OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.

debian
почти 12 лет назад

OpenStack Image Registry and Delivery Service (Glance) 2013.2 through ...

EPSS

Процентиль: 19%
0.00062
Низкий

5.1 Medium

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-532