Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmqq-r32m-87c5

Опубликовано: 29 авг. 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 4.9

Описание

python-oslo-utils has improper password parsing

A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext

Пакеты

Наименование

oslo-utils

pip
Затронутые версииВерсия исправления

< 4.10.1

4.10.1

EPSS

Процентиль: 57%
0.00347
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-522
CWE-532

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 3 лет назад

A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.

CVSS3: 6
redhat
почти 4 года назад

A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.

CVSS3: 4.9
nvd
больше 3 лет назад

A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.

CVSS3: 4.9
debian
больше 3 лет назад

A flaw was found in python-oslo-utils. Due to improper parsing, passwo ...

suse-cvrf
7 месяцев назад

Security update for python-oslo.utils

EPSS

Процентиль: 57%
0.00347
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-522
CWE-532