zhmcclient logs password-like properties in clear text
CVE-2024-53865
8.3HIGH
What is CVE-2024-53865?
The zhmcclient library, used for interfacing with IBM Z HMC Web Services API, has a vulnerability that allows sensitive password-like properties to be logged in clear text. This occurs under certain conditions when users create or update partitions, logical partitions (LPARs), or HMC user accounts within the library. Specific properties such as 'boot-ftp-password', 'ssc-master-pw', and 'bind-password' can be exposed in the log files if the corresponding logging functionality is enabled. The issue affects only users of the zhmcclient package who utilize specific API functions. An upgrade to zhmcclient version 1.18.1 is highly recommended to mitigate this risk, as there are currently no known workarounds.
Affected Version(s)
python-zhmcclient < 1.18.1