First published: Mon Jun 07 2021(Updated: )
Plain password from RHSM in the logs during OSP13 deployment with subscription-manager. overcloud_install.log contains a plaintext password after overcloud creation. See <a class="bz_bug_link bz_secure " title="" href="show_bug.cgi?id=1961709">https://bugzilla.redhat.com/show_bug.cgi?id=1961709</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Subscription Manager | ||
Red Hat OpenStack Platform 13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1968247 is considered moderate due to the exposure of plaintext passwords in logs.
To fix REDHAT-BUG-1968247, avoid logging sensitive information and review configuration settings for your logging level.
The affected products for REDHAT-BUG-1968247 include Red Hat Subscription Manager and Red Hat OpenStack Platform 13.
The REDHAT-BUG-1968247 vulnerability was reported as part of the OSP13 deployment process.
The impact of REDHAT-BUG-1968247 on security is significant as it could lead to unauthorized access if the plaintext passwords are exposed.