Summary: | <sys-auth/keystone-2013.1-r1: LDAP password disclosure in log files (CVE-2013-2006) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=956007 | ||
Whiteboard: | ~3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2013-04-24 07:56:33 UTC
keystone 2013.1-r1 contains the fix, old badness out of tree (In reply to comment #1) > keystone 2013.1-r1 contains the fix, old badness out of tree Thanks, Matthew. Closing noglsa for ~arch only. CVE-2013-2006 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2006): OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file. |