cbcvebase.
CVE-2022-0718
published 2022-08-29

CVE-2022-0718: A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any…

medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianpython-oslo.utils< python-oslo.utils 4.10.1-1 (bookworm)python-oslo.utils 4.10.1-1 (bookworm)
openstackoslo.utils< 4.10.14.10.1
openstackoslo.utils
openstackpython-oslo.utils
openstackpython-oslo.utils>= 0 < 4.6.1-0+deb11u14.6.1-0+deb11u1
openstackpython-oslo.utils>= 0 < 4.10.1-14.10.1-1
openstackpython-oslo.utils>= 0 < 4.10.1-14.10.1-1
openstackpython-oslo.utils>= 0 < 4.10.1-14.10.1-1
redhatopenshift_container_platform
redhatopenstack_platform

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv5.0MEDIUM