First published: Wed Jan 17 2024(Updated: )
A vulnerability was found in python-glance-store. The package logs access_key for glance-store when DEBUG log level is enabled.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Glance Store |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2258836 is considered high due to the potential exposure of sensitive access keys in logs.
To fix REDHAT-BUG-2258836, disable DEBUG logging in the python-glance-store configuration.
REDHAT-BUG-2258836 affects the OpenStack glance-store component.
A temporary workaround for REDHAT-BUG-2258836 is to manage logging levels to avoid sensitive information exposure.
The nature of REDHAT-BUG-2258836 is that it logs access keys when the DEBUG log level is enabled, risking exposure to unauthorized users.