A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.
The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Glance-store | Openstack | * | 4.7.0 (excluding) |
Red Hat OpenStack Platform 17.1 for RHEL 9 | RedHat | python-glance-store-0:2.5.1-17.1.20230621023901.el9ost | * |
Python-glance-store | Ubuntu | bionic | * |
Python-glance-store | Ubuntu | devel | * |
Python-glance-store | Ubuntu | focal | * |
Python-glance-store | Ubuntu | jammy | * |
Python-glance-store | Ubuntu | mantic | * |
Python-glance-store | Ubuntu | noble | * |
Python-glance-store | Ubuntu | oracular | * |
Python-glance-store | Ubuntu | xenial | * |