CVE Vulnerabilities

CVE-2024-4840

Cleartext Storage of Sensitive Information

Published: May 14, 2024 | Modified: Nov 25, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu

An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Red Hat OpenStack Platform 17.1 for RHEL 9 RedHat openstack-tripleo-heat-templates-0:14.3.1-17.1.20240919130756.el9ost *

Potential Mitigations

References