CVE-2021-3585: Infoleak
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.
Other sources
Plain password from RHSM in the logs during OSP13 deployment with subscription-manager. overcloudinstall.log contains a plaintext password after overcloud creation. See https://bugzilla.redhat.com/showbug.cgi?id=1961709
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-3585?
CVE-2021-3585 is a vulnerability found in openstack-tripleo-heat-templates that allows plain passwords from RHSM to exist in logs during OSP13 deployment with subscription-manager.
How severe is CVE-2021-3585?
CVE-2021-3585 has a severity rating of medium.
Which version of openstack-tripleo-heat-templates is affected by CVE-2021-3585?
The vulnerability affects openstack-tripleo-heat-templates up to version 8.4.1.
How can I fix CVE-2021-3585?
To fix CVE-2021-3585, it is recommended to update openstack-tripleo-heat-templates to a version that has the necessary security patches.
Where can I find more information about CVE-2021-3585?
You can find more information about CVE-2021-3585 on the Red Hat Bugzilla page and the Launchpad page.