CVE-2021-3585
published 2022-08-26CVE-2021-3585: A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.24%
15.5th percentile
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | tripleo-heat-templates | — | — |
| openstack | tripleo_heat_templates | < 8.4.1 | 8.4.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4qwm-996c-w925: A flaw was found in openstack-tripleo-heat-templates
ghsa_unreviewed·2022-08-27
CVE-2021-3585 [MEDIUM] CWE-312 GHSA-4qwm-996c-w925: A flaw was found in openstack-tripleo-heat-templates
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.
OSV
CVE-2021-3585: A flaw was found in openstack-tripleo-heat-templates
osv·2022-08-26·CVSS 5.5
CVE-2021-3585 [MEDIUM] CVE-2021-3585: A flaw was found in openstack-tripleo-heat-templates
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.
Red Hat
openstack-tripleo-heat-templates: Plain password logged in rhel-registration retry
vendor_redhat·2021-05-18·CVSS 5.5
CVE-2021-3585 [MEDIUM] CWE-200 openstack-tripleo-heat-templates: Plain password logged in rhel-registration retry
openstack-tripleo-heat-templates: Plain password logged in rhel-registration retry
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.
Statement: Because the flaw's impact is lower and Red Hat OpenStack Platform 13 will be retiring soon, no update will be provided at this time for the RHOSP13 openstack-tripleo-heat-templates package.
Package: openstack-tripleo-heat-templates (Red Hat OpenStack Platform 10 (Newton)) - Out of support scope
Package: openstack-tripleo-heat-templates (Red Hat OpenStack Platform 13 (Queens)) - Will not fix
Package:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3585https://bugs.launchpad.net/tripleo/+bug/1931132https://bugzilla.redhat.com/show_bug.cgi?id=1961709https://bugzilla.redhat.com/show_bug.cgi?id=1968247https://review.opendev.org/c/openstack/tripleo-heat-templates/+/791988https://access.redhat.com/security/cve/CVE-2021-3585https://bugs.launchpad.net/tripleo/+bug/1931132https://bugzilla.redhat.com/show_bug.cgi?id=1961709https://bugzilla.redhat.com/show_bug.cgi?id=1968247https://review.opendev.org/c/openstack/tripleo-heat-templates/+/791988
2022-08-26
Published