CVE Vulnerabilities

CVE-2024-1141

Logging of Excessive Data

Published: Feb 01, 2024 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.

Weakness

The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.

Affected Software

NameVendorStart VersionEnd Version
Glance-storeOpenstack*4.7.0 (excluding)
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatpython-glance-store-0:2.5.1-17.1.20230621023901.el9ost*
Python-glance-storeUbuntubionic*
Python-glance-storeUbuntudevel*
Python-glance-storeUbuntuesm-infra/focal*
Python-glance-storeUbuntufocal*
Python-glance-storeUbuntujammy*
Python-glance-storeUbuntumantic*
Python-glance-storeUbuntunoble*
Python-glance-storeUbuntuoracular*
Python-glance-storeUbuntuplucky*
Python-glance-storeUbuntuquesting*
Python-glance-storeUbuntuxenial*

Potential Mitigations

References