First published: Mon Feb 21 2022(Updated: )
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Openstack Oslo.utils | <4.10.1 | |
Openstack Oslo.utils | =4.12.0 | |
Redhat Openshift Container Platform | =4.0 | |
Redhat Openstack Platform | =16.1 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
pip/oslo-utils | <4.10.1 | 4.10.1 |
redhat/python-oslo-utils | <0:3.41.6-1.20220426095230.f4deaad.el8 | 0:3.41.6-1.20220426095230.f4deaad.el8 |
redhat/python-oslo-utils | <0:3.41.6-2.20220111011750.el8 | 0:3.41.6-2.20220111011750.el8 |
debian/python-oslo.utils | <=4.6.0-2<=4.6.1-0+deb11u1 | 6.0.1-2 7.3.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0718 is a vulnerability found in python-oslo-utils that causes incorrect masking of passwords with a double quote in them.
CVE-2022-0718 affects Openstack Oslo.utils versions 4.10.1 and 4.12.0.
CVE-2022-0718 affects Redhat Openshift Container Platform version 4.0.
CVE-2022-0718 affects Redhat Openstack Platform version 16.1.
CVE-2022-0718 affects Debian Debian Linux versions 10.0 and 11.0.
To fix CVE-2022-0718 in Openstack Oslo.utils, upgrade to version 4.12.1 or later.
To fix CVE-2022-0718 in Redhat Openshift Container Platform, apply the recommended patches or updates provided by Redhat.
To fix CVE-2022-0718 in Redhat Openstack Platform, apply the recommended patches or updates provided by Redhat.
To fix CVE-2022-0718 in Debian Debian Linux, upgrade to the latest version of the affected package or apply the recommended updates from the Debian security team.
CVE-2022-0718 has a severity rating of medium.
The CWE identifiers for CVE-2022-0718 are CWE-532 and CWE-522.
You can find more information about CVE-2022-0718 at the following references: [1] [2] [3]