CVE-2015-3646
published 2015-05-12CVE-2015-3646: OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote…
PriorityP418medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.88%
85.3th percentile
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2015.1.0-1 (bookworm) | keystone 2015.1.0-1 (bookworm) |
| openstack | keystone | >= 0 < 2015.1.0-1 | 2015.1.0-1 |
| openstack | keystone | >= 0 < 2015.1.0-1 | 2015.1.0-1 |
| openstack | keystone | >= 0 < 2015.1.0-1 | 2015.1.0-1 |
| openstack | keystone | >= 0 < 2015.1.0-1 | 2015.1.0-1 |
| openstack | keystone | >= 2011.3 < 2014.1.5 | 2014.1.5 |
| openstack | keystone | >= 2014.1 < 2014.1.5 | 2014.1.5 |
| openstack | keystone | >= 2014.2 < 2014.2.4 | 2014.2.4 |
| openstack | keystone | >= 2014.2.0 < 2014.2.4 | 2014.2.4 |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Keystone Logs Passwords
osv·2022-05-13
CVE-2015-3646 [MEDIUM] OpenStack Keystone Logs Passwords
OpenStack Keystone Logs Passwords
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
GHSA
OpenStack Keystone Logs Passwords
ghsa·2022-05-13
CVE-2015-3646 [MEDIUM] CWE-200 OpenStack Keystone Logs Passwords
OpenStack Keystone Logs Passwords
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
OSV
CVE-2015-3646: OpenStack Identity (Keystone) before 2014
osv·2015-05-12·CVSS 4.0
CVE-2015-3646 [MEDIUM] CVE-2015-3646: OpenStack Identity (Keystone) before 2014
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
Red Hat
openstack-keystone: cache backend password leak in log (OSSA 2015-008)
vendor_redhat·2015-05-04·CVSS 4.0
CVE-2015-3646 [MEDIUM] CWE-732 openstack-keystone: cache backend password leak in log (OSSA 2015-008)
openstack-keystone: cache backend password leak in log (OSSA 2015-008)
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
Statement: While this issue does occur in openstack-keystone packages as shipped in Red Hat Enterprise Linux OpenStack Platform versions 5 and 6 it is not believed to be exploitable as access to the keystone logs is restricted with file-system permissions.
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Packag
Debian
CVE-2015-3646: keystone - OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs ...
vendor_debian·2015·CVSS 4.0
CVE-2015-3646 [MEDIUM] CVE-2015-3646: keystone - OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs ...
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
Scope: local
bookworm: resolved (fixed in 2015.1.0-1)
bullseye: resolved (fixed in 2015.1.0-1)
forky: resolved (fixed in 2015.1.0-1)
sid: resolved (fixed in 2015.1.0-1)
trixie: resolved (fixed in 2015.1.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008) [fedora-all]
bugzilla·2015-05-05·CVSS 4.0
CVE-2015-3646 [MEDIUM] CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008) [fedora-all]
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008)
bugzilla·2015-05-05·CVSS 4.0
CVE-2015-3646 [MEDIUM] CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008)
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008)
The following flaw was found in Keystone:
Eric Brown from VMware reported a vulnerability in Keystone. The backend_argument configuration option content is being logged, and it may contain sensitive information for specific backends (like a password for MongoDB). An attacker with read access to Keystone logs may therefore obtain sensitive data about certain backends. All Keystone setups are potentially impacted.
Upstream patches:
https://review.openstack.org/175519 (Icehouse)
https://review.openstack.org/173116 (Juno)
Upstream bug:
https://launchpad.net/bugs/1443598
Upstream advisory:
http://www.openwall.com/lists/oss-security/2015/05/05/11
Discussion:
Created openstack-keystone tracking bugs for
Bugzilla
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008) [openstack-rdo]
bugzilla·2015-05-05·CVSS 4.0
CVE-2015-3646 [MEDIUM] CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008) [openstack-rdo]
CVE-2015-3646 openstack-keystone: cache backend password leak in log (OSSA 2015-008) [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of RDO.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
openstack-rdo tracking bug for opens
http://lists.openstack.org/pipermail/openstack-announce/2015-May/000356.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/74456https://bugs.launchpad.net/keystone/+bug/1443598http://lists.openstack.org/pipermail/openstack-announce/2015-May/000356.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/74456https://bugs.launchpad.net/keystone/+bug/1443598
2015-05-12
Published