4
CVSSv2

CVE-2015-3646

Published: 12/05/2015 Updated: 02/06/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

OpenStack Identity (Keystone) prior to 2014.1.5 and 2014.2.x prior to 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone

oracle solaris 11.2

Vendor Advisories

OpenStack Identity (Keystone) before 201415 and 20142x before 201424 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs ...