zhmcclient logs password-like properties in clear text
CVE-2024-53865
What is CVE-2024-53865?
The zhmcclient library, used for interfacing with IBM Z HMC Web Services API, has a vulnerability that allows sensitive password-like properties to be logged in clear text. This occurs under certain conditions when users create or update partitions, logical partitions (LPARs), or HMC user accounts within the library. Specific properties such as 'boot-ftp-password', 'ssc-master-pw', and 'bind-password' can be exposed in the log files if the corresponding logging functionality is enabled. The issue affects only users of the zhmcclient package who utilize specific API functions. An upgrade to zhmcclient version 1.18.1 is highly recommended to mitigate this risk, as there are currently no known workarounds.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
python-zhmcclient < 1.18.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
