UNKNOWN PyPI

OpenStack Keystone Sensitive information disclosure via log files

GHSA-rxrm-xvp4-jqvh · CVE-2013-2006

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.

Ready to move

Start Securing

Free, no credit card | First findings in minutes