Sensitive Information Exposure in OpenStack Identity by OpenStack Foundation
CVE-2015-3646
Currently unrated
What is CVE-2015-3646?
OpenStack Identity (Keystone) prior to version 2014.1.5 and 2014.2.x prior to 2014.2.4 exhibits a vulnerability where the backend_argument configuration option content is logged. This flaw enables remote authenticated users to gain unauthorized access to sensitive information, including passwords, by reading log files. Organizations leveraging this service should ensure they upgrade to patched versions to mitigate the risk of information exposure.