An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:9978 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-4840 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2280249 | issue tracking |