A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.
Storing a password in plaintext may result in a system compromise.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openstack_platform | Redhat | 16.2 (including) | 16.2 (including) |
Openstack | Ubuntu | bionic | * |
Openstack | Ubuntu | trusty | * |
Openstack | Ubuntu | xenial | * |