CVE-2015-3646
OpenStack Identity (Keystone) <2014.1.5-2014.2.4 - Info Disclosure
Title source: llmDescription
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
References (4)
Scores
EPSS
0.0015
EPSS Percentile
35.0%
Classification
CWE
CWE-200
Status
draft
Affected Products (3)
openstack/keystone
< 2014.1.5
oracle/solaris
pypi/keystone
< 2014.1.5PyPI
Timeline
Published
May 12, 2015
Tracked Since
Feb 18, 2026