[Openstack-security] [Bug 1320098] Change abandoned on python-neutronclient (master)

OpenStack Infra 1320098 at bugs.launchpad.net
Tue Sep 16 02:58:22 UTC 2014


Change abandoned by Xu Han Peng (xuhanp at linux.vnet.ibm.com) on branch: master
Review: https://review.openstack.org/93866
Reason: Abandon this patch because X-Auth-Token has been replaced by "TOKEN_REDACTED"

by this keystone client patch:
 https://github.com/openstack/python-keystoneclient/commit/605577192d7158ecf40bd9a94b7cf3acc2ce1c95

-- 
You received this bug notification because you are a member of OpenStack
Security Group, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1320098

Title:
  neutronclient debug logging includes keystone auth token

Status in Python client library for Neutron:
  In Progress

Bug description:
  neutronclient is logging the auth token in the nova logs. Since the
  logs are world-readable, this means anyone user on this system can see
  the auth token, which they can then use to get OpenStack administrator
  access.

To manage notifications about this bug go to:
https://bugs.launchpad.net/python-neutronclient/+bug/1320098/+subscriptions




More information about the Openstack-security mailing list