OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| keystone(PyPI) | 2011.3 | 2014.1.5 | N/A |
| keystone(PyPI) | 2014.2 | 2014.2.4 | N/A |
CVSS Metrics