A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.
The product stores a password in plaintext within resources such as memory or files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openstack_platform | Redhat | 16.2 (including) | 16.2 (including) |
Openstack | Ubuntu | bionic | * |
Openstack | Ubuntu | trusty | * |
Openstack | Ubuntu | xenial | * |