{"id":"GHSA-rxrm-xvp4-jqvh","summary":"OpenStack Keystone Sensitive information disclosure via log files","details":"OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.","aliases":["CVE-2013-2006"],"modified":"2024-11-22T17:51:18Z","published":"2022-05-17T04:44:52Z","database_specific":{"nvd_published_at":"2013-05-21T18:55:00Z","cwe_ids":["CWE-200"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2024-05-14T21:17:01Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2006"},{"type":"WEB","url":"https://github.com/openstack/keystone/commit/c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd"},{"type":"WEB","url":"https://github.com/openstack/keystone/commit/d43e2a51a1ed7adbed3c5ddf001d46bc4a824ae8"},{"type":"WEB","url":"https://bugs.launchpad.net/keystone/+bug/1172195"},{"type":"WEB","url":"https://bugs.launchpad.net/ossn/+bug/1168252"},{"type":"PACKAGE","url":"https://github.com/openstack/keystone"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2013-40.yaml"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105916.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106220.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2013-0806.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/04/24/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/04/24/2"},{"type":"WEB","url":"http://www.securityfocus.com/bid/59411"}],"affected":[{"package":{"name":"keystone","ecosystem":"PyPI","purl":"pkg:pypi/keystone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.0a0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rxrm-xvp4-jqvh/GHSA-rxrm-xvp4-jqvh.json"}}],"schema_version":"1.9.0"}