PT-2022-13384 · Openstack+5 · Python-Oslo-Utils+5

Marian Rehak

·

Published

2022-03-23

·

Updated

2025-07-21

·

CVE-2022-0718

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions python-oslo-utils (affected versions not specified)
Description A flaw was found in python-oslo-utils due to improper parsing. Passwords with a double quote (") in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insertion into Log File

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-0718
DLA-3106-1
DLA-3870-1
GHSA-WMQQ-R32M-87C5
MGASA-2022-0189
PYSEC-2022-258
RHSA-2022:0993
RHSA-2022:8873
SUSE-SU-2025:02448-1
SUSE-SU-2025_02448-1
USN-5369-1

Affected Products

Astra Linux
Debian
Linuxmint
Suse
Ubuntu
Python-Oslo-Utils