REDHAT-BUG-2258836: Medium severity openstack glance store vulnerability
Published Jan 17, 2024
·Updated
A vulnerability was found in python-glance-store. The package logs accesskey for glance-store when DEBUG log level is enabled.
Affected Software
1 affected component
Openstack glance-store
Event History
Jan 17, 2024
Data Sourced
via Red Hat·04:36 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2258836?
The severity of REDHAT-BUG-2258836 is considered high due to the potential exposure of sensitive access keys in logs.
2
How do I fix REDHAT-BUG-2258836?
To fix REDHAT-BUG-2258836, disable DEBUG logging in the python-glance-store configuration.
3
What components are affected by REDHAT-BUG-2258836?
REDHAT-BUG-2258836 affects the OpenStack glance-store component.
4
Is there a workaround for REDHAT-BUG-2258836?
A temporary workaround for REDHAT-BUG-2258836 is to manage logging levels to avoid sensitive information exposure.
5
What is the nature of the vulnerability in REDHAT-BUG-2258836?
The nature of REDHAT-BUG-2258836 is that it logs access keys when the DEBUG log level is enabled, risking exposure to unauthorized users.