CVE Vulnerabilities

CVE-2024-1141

Logging of Excessive Data

Published: Feb 01, 2024 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.

Weakness

The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.

Affected Software

Name Vendor Start Version End Version
Glance-store Openstack * 4.7.0 (excluding)
Red Hat OpenStack Platform 17.1 for RHEL 9 RedHat python-glance-store-0:2.5.1-17.1.20230621023901.el9ost *
Python-glance-store Ubuntu bionic *
Python-glance-store Ubuntu devel *
Python-glance-store Ubuntu focal *
Python-glance-store Ubuntu jammy *
Python-glance-store Ubuntu mantic *
Python-glance-store Ubuntu noble *
Python-glance-store Ubuntu oracular *
Python-glance-store Ubuntu xenial *

Potential Mitigations

References