Description
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: High
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages5 packages
Also affects: Debian Linux 10.0, 11.0, Openshift Container Platform 4.0
🔴Vulnerability Details
5GHSApython-oslo-utils has improper password parsing↗2022-08-29 ▶ CVEListCVE-2022-0718: A flaw was found in python-oslo-utils↗2022-08-29 ▶ OSVpython-oslo-utils has improper password parsing↗2022-08-29 ▶ OSVCVE-2022-0718: A flaw was found in python-oslo-utils↗2022-08-29 ▶ OSVlibxmltok vulnerabilities↗2022-07-19 ▶ 📋Vendor Advisories
3Ubuntuoslo.utils vulnerability↗2022-04-07 ▶ Red Hatpython-oslo-utils: incorrect password masking in debug output↗2022-02-21 ▶ DebianCVE-2022-0718: python-oslo.utils - A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a...↗2022 ▶