CVE-2022-0718
published 2022-08-29CVE-2022-0718: A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any…
PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
1.33%
68.0th percentile
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | python-oslo.utils | < python-oslo.utils 4.10.1-1 (bookworm) | python-oslo.utils 4.10.1-1 (bookworm) |
| openstack | oslo.utils | < 4.10.1 | 4.10.1 |
| openstack | oslo.utils | — | — |
| openstack | python-oslo.utils | — | — |
| openstack | python-oslo.utils | >= 0 < 4.6.1-0+deb11u1 | 4.6.1-0+deb11u1 |
| openstack | python-oslo.utils | >= 0 < 4.10.1-1 | 4.10.1-1 |
| openstack | python-oslo.utils | >= 0 < 4.10.1-1 | 4.10.1-1 |
| openstack | python-oslo.utils | >= 0 < 4.10.1-1 | 4.10.1-1 |
| redhat | openshift_container_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv5.0MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
python-oslo-utils has improper password parsing
ghsa·2022-08-29
CVE-2022-0718 [MEDIUM] CWE-522 python-oslo-utils has improper password parsing
python-oslo-utils has improper password parsing
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext
OSV
python-oslo-utils has improper password parsing
osv·2022-08-29
CVE-2022-0718 [MEDIUM] python-oslo-utils has improper password parsing
python-oslo-utils has improper password parsing
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext
OSV
CVE-2022-0718: A flaw was found in python-oslo-utils
osv·2022-08-29·CVSS 4.9
CVE-2022-0718 [MEDIUM] CVE-2022-0718: A flaw was found in python-oslo-utils
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
OSV
libxmltok vulnerabilities
osv·2022-07-19·CVSS 5.0
CVE-2012-1148 libxmltok vulnerabilities
libxmltok vulnerabilities
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2022-25235)
It was discovered
Ubuntu
oslo.utils vulnerability
vendor_ubuntu·2022-04-07
CVE-2022-0718 oslo.utils vulnerability
Title: oslo.utils vulnerability
Summary: oslo.utils could be made to expose sensitive information if it received
a specially crafted input.
It was discovered that oslo.utils incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-oslo-utils: incorrect password masking in debug output
vendor_redhat·2022-02-21·CVSS 4.9
CVE-2022-0718 [MEDIUM] CWE-532 python-oslo-utils: incorrect password masking in debug output
python-oslo-utils: incorrect password masking in debug output
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
Package: python-oslo-utils (Red Hat OpenShift Container Platform 4) - Affected
Package: python-oslo-utils (Red Hat OpenStack Platform 13 (Queens)) - Out of support scope
Package: python-oslo-utils (Red Hat Storage 3) - Will not fix
Debian
CVE-2022-0718: python-oslo.utils - A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a...
vendor_debian·2022·CVSS 4.9
CVE-2022-0718 [MEDIUM] CVE-2022-0718: python-oslo.utils - A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a...
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
Scope: local
bookworm: resolved (fixed in 4.10.1-1)
bullseye: resolved (fixed in 4.6.1-0+deb11u1)
forky: resolved (fixed in 4.10.1-1)
sid: resolved (fixed in 4.10.1-1)
trixie: resolved (fixed in 4.10.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-0718https://bugs.launchpad.net/oslo.utils/+bug/1949623https://bugzilla.redhat.com/show_bug.cgi?id=2056850https://lists.debian.org/debian-lts-announce/2022/09/msg00015.htmlhttps://opendev.org/openstack/oslo.utils/commit/6e17ae1f7959c64dfd20a5f67edf422e702426aahttps://security-tracker.debian.org/tracker/CVE-2022-0718https://access.redhat.com/security/cve/CVE-2022-0718https://bugs.launchpad.net/oslo.utils/+bug/1949623https://bugzilla.redhat.com/show_bug.cgi?id=2056850https://lists.debian.org/debian-lts-announce/2022/09/msg00015.htmlhttps://opendev.org/openstack/oslo.utils/commit/6e17ae1f7959c64dfd20a5f67edf422e702426aahttps://security-tracker.debian.org/tracker/CVE-2022-0718
2022-08-29
Published