python-oslo-utils: incorrect password masking in debug output
Published Aug 29, 2022
6.9
MEDIUMCVSS 4.0
EPSS 1.74%
Description
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
Affected products
- Vendor n/a Product Openstack/python-Oslo.utils Defaultn/a
- Version Affects all versions, Fixed in 4.10.1, 4.12.1.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Openstack/python-Oslo.utils | n/a |
|
Configuration 1
- < 4.10.1
- 4.12.0
Configuration 2
- 4.0
- 16.1
Configuration 3
- 10.0
- 11.0
No data.
Red Hat OpenStack Platform 16.1
python-oslo-utils-0:3.41.6-1.20220426095230.f4deaad.el8ost
Fixed · RHSA-2022:8873
Red Hat OpenStack Platform 16.2
python-oslo-utils-0:3.41.6-2.20220111011750.el8ost
Fixed · RHSA-2022:0993
Red Hat OpenShift Container Platform 4
python-oslo-utils
Affected
Red Hat OpenStack Platform 13 (Queens)
python-oslo-utils
Out of support scope
Red Hat Storage 3
python-oslo-utils
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 16.1 | python-oslo-utils-0:3.41.6-1.20220426095230.f4deaad.el8ost | Fixed | RHSA-2022:8873 |
| Red Hat OpenStack Platform 16.2 | python-oslo-utils-0:3.41.6-2.20220111011750.el8ost | Fixed | RHSA-2022:0993 |
| Red Hat OpenShift Container Platform 4 | python-oslo-utils | Affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-oslo-utils | Out of support scope | n/a |
| Red Hat Storage 3 | python-oslo-utils | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/errata/RHSA-2022:0993
- https://access.redhat.com/errata/RHSA-2022:8873
- https://access.redhat.com/security/cve/CVE-2022-0718 x_refsource_MISCThird Party AdvisoryVendor Advisory
- https://bugs.launchpad.net/oslo.utils/+bug/1949623 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2056850 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-wmqq-r32m-87c5 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/oslo-utils/PYSEC-2022-258.yaml
- https://lists.debian.org/debian-lts-announce/2022/09/msg00015.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0718
- https://opendev.org/openstack/oslo.utils/commit/6e17ae1f7959c64dfd20a5f67edf422e702426aa x_refsource_MISCPatchVendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2022-0718 x_refsource_MISCPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0718
Change history (0)
No recorded changes yet.