Severity
4.0MEDIUM
EPSS
0.2%
top 60.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 13

Description

OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages4 packages

NVDopenstack/keystone2014.12014.1.5+1
PyPIkeystone2011.32014.1.5+1
Debiankeystone< 2015.1.0-1+3
NVDoracle/solaris11.2

Patches

🔴Vulnerability Details

4
OSV
OpenStack Keystone Logs Passwords2022-05-13
GHSA
OpenStack Keystone Logs Passwords2022-05-13
CVEList
CVE-2015-3646: OpenStack Identity (Keystone) before 20142015-05-12
OSV
CVE-2015-3646: OpenStack Identity (Keystone) before 20142015-05-12

📋Vendor Advisories

2
Red Hat
openstack-keystone: cache backend password leak in log (OSSA 2015-008)2015-05-04
Debian
CVE-2015-3646: keystone - OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs ...2015

💬Community

3
Bugzilla
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008) [fedora-all]2015-05-05
Bugzilla
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008)2015-05-05
Bugzilla
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008) [openstack-rdo]2015-05-05
CVE-2015-3646 (MEDIUM CVSS 4) | OpenStack Identity (Keystone) befor | cvebase.io