Описание
OpenStack Keystone Sensitive information disclosure via log files
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-2006
- https://github.com/openstack/keystone/commit/c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd
- https://github.com/openstack/keystone/commit/d43e2a51a1ed7adbed3c5ddf001d46bc4a824ae8
- https://bugs.launchpad.net/keystone/+bug/1172195
- https://bugs.launchpad.net/ossn/+bug/1168252
- https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2013-40.yaml
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105916.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106220.html
- http://rhn.redhat.com/errata/RHSA-2013-0806.html
- http://www.openwall.com/lists/oss-security/2013/04/24/1
- http://www.openwall.com/lists/oss-security/2013/04/24/2
- http://www.securityfocus.com/bid/59411
Пакеты
keystone
< 8.0.0a0
8.0.0a0
Связанные уязвимости
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode loggin ...