A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2056850 | issue tracking third party advisory patch |
https://bugs.launchpad.net/oslo.utils/+bug/1949623 | issue tracking patch exploit third party advisory |
https://opendev.org/openstack/oslo.utils/commit/6e17ae1f7959c64dfd20a5f67edf422e702426aa | patch vendor advisory |
https://security-tracker.debian.org/tracker/CVE-2022-0718 | third party advisory patch |
https://access.redhat.com/security/cve/CVE-2022-0718 | third party advisory |
https://lists.debian.org/debian-lts-announce/2022/09/msg00015.html | third party advisory mailing list |