CVE-2024-4840: Red Hat Openstack Platform 16.2

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.

Affected products

  • Red Hat Red Hat Openstack Platform 16.2
  • Red Hat Red Hat Openstack Platform 17.1 For Rhel 9: before 0:14.3.1-17.1.20240919130756.el9ost (fixed in 0:14.3.1-17.1.20240919130756.el9ost)

Published 2024-05-14. Last modified 2026-06-17.