glance-store logs s3 access keys
Moderate severity
GitHub Reviewed
Published
Feb 1, 2024
to the GitHub Advisory Database
•
Updated May 23, 2024
Description
Published by the National Vulnerability Database
Feb 1, 2024
Published to the GitHub Advisory Database
Feb 1, 2024
Reviewed
Feb 5, 2024
Last updated
May 23, 2024
A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.
References