CVE-2015-3646: Openstack Keystone
Medium severity, CVSS 4.0. EPSS: 2.9% chance of exploitation in the next 30 days.
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
Affected products
- Openstack Keystone: from 2014.1, before 2014.1.5 (fixed in 2014.1.5); from 2014.2.0, before 2014.2.4 (fixed in 2014.2.4)
- Oracle Solaris: version 11.2 only
Published 2015-05-12. Last modified 2026-06-17.