[Openstack-security] [Bug 1320098] Re: neutronclient debug logging includes keystone auth token

Robert Clark 1320098 at bugs.launchpad.net
Mon Jun 2 12:50:56 UTC 2014


Limited security impact because it's client side but certainly an issue
that needs to be fixed.

-Rob

-- 
You received this bug notification because you are a member of OpenStack
Security Group, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1320098

Title:
  neutronclient debug logging includes keystone auth token

Status in Python client library for Neutron:
  In Progress

Bug description:
  neutronclient is logging the auth token in the nova logs. Since the
  logs are world-readable, this means anyone user on this system can see
  the auth token, which they can then use to get OpenStack administrator
  access.

To manage notifications about this bug go to:
https://bugs.launchpad.net/python-neutronclient/+bug/1320098/+subscriptions




More information about the Openstack-security mailing list