The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.