CVE-2015-3646
12.05.2015, 19:59
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openstack | keystone | 2014.1 ≤ 𝑥 < 2014.1.5 |
| openstack | keystone | 2014.2.0 ≤ 𝑥 < 2014.2.4 |
| oracle | solaris | 11.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References