[Openstack-security] [Bug 1750074] Fix included in openstack/cinder 13.0.0.0b1

OpenStack Infra 1750074 at bugs.launchpad.net
Thu Apr 19 14:00:11 UTC 2018


This issue was fixed in the openstack/cinder 13.0.0.0b1 development
milestone.

-- 
You received this bug notification because you are a member of OpenStack
Security SIG, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1750074

Title:
  Cinder logs rabbitmq password on connection log

Status in Cinder:
  Fix Released
Status in Manila:
  Fix Released
Status in OpenStack Security Advisory:
  Won't Fix

Bug description:
  Cinder may log rabbitmq password on connection when DEBUG is on.

  Example on cinder-scheduler.log file after enabling DEBUG:
  (Password has been replaced with XXX)

  2018-02-05 19:21:52.721 35 DEBUG cinder.service [req-a2dbe0dd-
  14c9-4123-a69a-3623e5f0a4d7 - - - - -] transport_url :
  rabbit://guest:XXX@10.10.10.1:5672,guest:XXX@10.10.10.2:5672,guest:XXX@10.10.10.3:5672
  wait /usr/lib/python2.7/site-packages/cinder/service.py:611

  In a production environment, this is pretty bad.

To manage notifications about this bug go to:
https://bugs.launchpad.net/cinder/+bug/1750074/+subscriptions




More information about the Openstack-security mailing list