CVE-2024-1141: Glance-store: glance store access key logged in debug log level
A vulnerability was found in python-glance-store. The issue occurs when the package logs the accesskey for the glance-store when the DEBUG log level is enabled.
Other sources
A vulnerability was found in python-glance-store. The package logs accesskey for glance-store when DEBUG log level is enabled.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/python-glance-storeto a version that resolves this vulnerability.Fixed in 2.0.0-0ubuntu4.3 - Upgrade
Upgrade
ubuntu/python-glance-storeto a version that resolves this vulnerability.Fixed in 3.0.0-0ubuntu1.4 - Upgrade
Upgrade
ubuntu/python-glance-storeto a version that resolves this vulnerability.Fixed in 4.6.1-0ubuntu1.1 - Configuration
Do not run glance-store with DEBUG log level enabled; set logging to a non-DEBUG level so the glance-store access_key is not logged.
glance-store (python-glance-store) log level (DEBUG) = disable DEBUG / set to a non-Debug log level
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1141?
The severity of CVE-2024-1141 is classified as moderate due to the potential exposure of sensitive information.
How do I fix CVE-2024-1141?
To fix CVE-2024-1141, upgrade to python-glance-store version 4.7.0 or later.
What versions are affected by CVE-2024-1141?
CVE-2024-1141 affects python-glance-store versions up to and including 4.6.1.
Is CVE-2024-1141 relevant for OpenStack installations?
Yes, CVE-2024-1141 is relevant for OpenStack installations using affected versions of glance-store.
What types of data are exposed by CVE-2024-1141?
CVE-2024-1141 can expose sensitive data such as access keys when debug logging is enabled.