First published: Mon May 13 2024(Updated: )
Reference: <a class="bz_bug_link bz_secure " title="" href="show_bug.cgi?id=2279386">https://bugzilla.redhat.com/show_bug.cgi?id=2279386</a> Description of problem: It was found that DB_ROOT_PASSWORD and RABBITMQ_CLUSTER_COOKIE found in cleartext in /var/log/messages. This seems to happen when mysql container is bootstrapped. Version-Release number of selected component (if applicable): 17.1, as well as 16.2 How reproducible: 100% Steps to Reproduce: 1. run undercloud deploy or upgrade, or re-run undercloud install command Actual results: clear text passwords printed in logs Expected results: clear text passwords not printed in logs Additional info: This seems to happen even when undercloud_debug = false
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack Services on OpenShift | >=16.2<=17.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2280249 is considered high due to sensitive credentials being exposed in cleartext.
To fix REDHAT-BUG-2280249, ensure that sensitive information in logs is configured not to include plaintext passwords.
REDHAT-BUG-2280249 affects Red Hat OpenStack versions between 16.2 and 17.1.
REDHAT-BUG-2280249 exposes DB_ROOT_PASSWORD and RABBITMQ_CLUSTER_COOKIE in the clear within the /var/log/messages file.
After resolving REDHAT-BUG-2280249, monitor log files to ensure that sensitive data is not being logged unintentionally.