A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.
Storing a password in plaintext may result in a system compromise.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2022-3261 | vdb entry vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2128834 | vendor advisory issue tracking |