CVE-2022-0718: Medium severity Openstack Oslo.utils vulnerability
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext
Other sources
maskpasswords doesn't mask characters following a " so if a user has a password containing a " in the middle such as pass"word , we would see "word in the debug output.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-0718?
CVE-2022-0718 is a vulnerability found in python-oslo-utils that causes incorrect masking of passwords with a double quote in them.
How does CVE-2022-0718 affect Openstack Oslo.utils?
CVE-2022-0718 affects Openstack Oslo.utils versions 4.10.1 and 4.12.0.
How does CVE-2022-0718 affect Redhat Openshift Container Platform?
CVE-2022-0718 affects Redhat Openshift Container Platform version 4.0.
How does CVE-2022-0718 affect Redhat Openstack Platform?
CVE-2022-0718 affects Redhat Openstack Platform version 16.1.
How does CVE-2022-0718 affect Debian Debian Linux?
CVE-2022-0718 affects Debian Debian Linux versions 10.0 and 11.0.
How do I fix CVE-2022-0718 in Openstack Oslo.utils?
To fix CVE-2022-0718 in Openstack Oslo.utils, upgrade to version 4.12.1 or later.
How do I fix CVE-2022-0718 in Redhat Openshift Container Platform?
To fix CVE-2022-0718 in Redhat Openshift Container Platform, apply the recommended patches or updates provided by Redhat.
How do I fix CVE-2022-0718 in Redhat Openstack Platform?
To fix CVE-2022-0718 in Redhat Openstack Platform, apply the recommended patches or updates provided by Redhat.
How do I fix CVE-2022-0718 in Debian Debian Linux?
To fix CVE-2022-0718 in Debian Debian Linux, upgrade to the latest version of the affected package or apply the recommended updates from the Debian security team.
What is the severity of CVE-2022-0718?
CVE-2022-0718 has a severity rating of medium.
What are the CWE identifiers for CVE-2022-0718?
The CWE identifiers for CVE-2022-0718 are CWE-532 and CWE-522.
Where can I find more information about CVE-2022-0718?
You can find more information about CVE-2022-0718 at the following references: [1] [2] [3]