Rhosp-director: cleartext passwords exposed in logs
Published May 13, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.20%
Description
An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat OpenStack Platform 16.2 | affected |
No data.
No data.
Red Hat OpenStack Platform 17.1 for RHEL 9
openstack-tripleo-heat-templates-0:14.3.1-17.1.20240919130756.el9ost
Fixed · RHSA-2024:9978
Red Hat OpenStack Platform 16.2
rhosp-director
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 17.1 for RHEL 9 | openstack-tripleo-heat-templates-0:14.3.1-17.1.20240919130756.el9ost | Fixed | RHSA-2024:9978 |
| Red Hat OpenStack Platform 16.2 | rhosp-director | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/errata/RHSA-2024:9978 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-4840 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2280249 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44553 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-4840
- https://www.cve.org/CVERecord?id=CVE-2024-4840
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:9978 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2024-4840 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2280249 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44553 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-4840 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-4840 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data