CVE-2015-3646: Openstack Keystone

Medium severity, CVSS 4.0. EPSS: 2.9% chance of exploitation in the next 30 days.

OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.

Affected products

  • Openstack Keystone: from 2014.1, before 2014.1.5 (fixed in 2014.1.5); from 2014.2.0, before 2014.2.4 (fixed in 2014.2.4)
  • Oracle Solaris: version 11.2 only

Published 2015-05-12. Last modified 2026-06-17.