4.9
CVE-2022-0718
- EPSS 0.33%
- Published 29.08.2022 15:15:09
- Last modified 21.11.2024 06:39:15
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
Data is provided by the National Vulnerability Database (NVD)
Openstack ≫ Oslo.Utils Version < 4.10.1
Openstack ≫ Oslo.Utils Version4.12.0
Redhat ≫ Openshift Container Platform Version4.0
Redhat ≫ Openstack Platform Version16.1
Debian ≫ Debian Linux Version10.0
Debian ≫ Debian Linux Version11.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.33% | 0.555 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.