Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv7j-2v4w-cjvh

Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью

Описание

OpenStack Glance logs user name and password in cleartext

store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.

Пакеты

Наименование

glance

pip
Затронутые версииВерсия исправления

>= 2012.1, < 2012.2.3

2012.2.3

EPSS

Процентиль: 79%
0.01203
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 13 лет назад

store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.

redhat
около 13 лет назад

store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.

nvd
почти 13 лет назад

store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.

debian
почти 13 лет назад

store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) bef ...

EPSS

Процентиль: 79%
0.01203
Низкий

Дефекты

CWE-200