[Openstack-security] [Bug 1336225] Re: Password is exposed in the log file

OpenStack Infra 1336225 at bugs.launchpad.net
Wed Jul 2 12:23:25 UTC 2014


Reviewed:  https://review.openstack.org/103842
Committed: https://git.openstack.org/cgit/openstack/heat/commit/?id=35cf2f7a3beb6ac5fd198aa6ce1cdb492a099cf2
Submitter: Jenkins
Branch:    master

commit 35cf2f7a3beb6ac5fd198aa6ce1cdb492a099cf2
Author: Kanagaraj Manickam <kanagaraj.manickam at hp.com>
Date:   Tue Jul 1 16:34:21 2014 +0530

    Don't expose password in heat-keystone-setup-domain logs
    
    heat-keystone-setup-domain is logging
    the password to the log file. This patch
    removes the logging as it's security concerns
    
    Change-Id: I0f017a9c114ac60ea9f5e0df012334ead8cb434a
    Closes-bug: #1336225


** Changed in: heat
       Status: In Progress => Fix Committed

-- 
You received this bug notification because you are a member of OpenStack
Security Group, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1336225

Title:
  Password is exposed in the log file

Status in Orchestration API (Heat):
  Fix Committed

Bug description:
  heat-keystone-setup-domain is logging the password to the log file.
  This defect is filed to remove the logging statement as its security
  concerns

To manage notifications about this bug go to:
https://bugs.launchpad.net/heat/+bug/1336225/+subscriptions




More information about the Openstack-security mailing list