CVE-2024-4840

MEDIUM

OpenStack Platform - Info Disclosure

Title source: llm
STIX 2.1

Description

An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (2)
Red Hat/Red Hat OpenStack Platform 16.2
Red Hat/Red Hat OpenStack Platform 17.1 for RHEL 9 0:14.3.1-17.1.20240919130756.el9ost
Published May 14, 2024
Tracked Since Feb 18, 2026