CVE-2022-3261
Publication date 15 September 2023
Last updated 11 February 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openstack | ||
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Ignored end of standard support | |
| 14.04 LTS trusty | Not in release |
Notes
john-breton
We are taking the same position that Debian has taken regarding this CVE. Namely, permission management for log files should be the purview of a system's local administrator. The information leak cannot occur unless some other vulnerability is exploited to first access the low files. As such this isn't a true vulnerability. Further there is no fix available upstream because they also don't view it as a valid CVE. As such we will be ignoring it.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
4.4 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N