[Openstack-security] [Bug 1320098] Re: neutronclient debug logging includes keystone auth token

Xu Han Peng pengxuhan at gmail.com
Wed Sep 17 05:24:02 UTC 2014


Mark as fixed since X-Auth-Token has been replaced by "TOKEN_REDACTED" by this keystone client patch:
 https://github.com/openstack/python-keystoneclient/commit/605577192d7158ecf40bd9a94b7cf3acc2ce1c95

** Changed in: python-neutronclient
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of OpenStack
Security Group, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1320098

Title:
  neutronclient debug logging includes keystone auth token

Status in Python client library for Neutron:
  Fix Released

Bug description:
  neutronclient is logging the auth token in the nova logs. Since the
  logs are world-readable, this means anyone user on this system can see
  the auth token, which they can then use to get OpenStack administrator
  access.

To manage notifications about this bug go to:
https://bugs.launchpad.net/python-neutronclient/+bug/1320098/+subscriptions




More information about the Openstack-security mailing list