[OSSA-2013-013] Updating password via keystoneclient CLI should be done securely (CVE-2013-2013)
Bug #938315 reported by
Jake Dahn
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Security Advisory |
Fix Released
|
Low
|
Jeremy Stanley | ||
python-keystoneclient |
Fix Released
|
High
|
Pradeep Kilambi |
Bug Description
Updating password via CLI should be done via a secure password prompt, not text.
current: keystone user-password-
expected: keystone user-password-
CVE References
tags: | added: python-keystoneclient |
Changed in keystone: | |
assignee: | nobody → Brian Waldon (bcwaldon) |
Changed in keystone: | |
status: | New → In Progress |
Changed in keystone: | |
status: | In Progress → Triaged |
assignee: | Brian Waldon (bcwaldon) → nobody |
Changed in keystone: | |
assignee: | nobody → adapaka bhavaniprasad (adapaka-prasad) |
assignee: | adapaka bhavaniprasad (adapaka-prasad) → nobody |
Changed in keystone: | |
assignee: | nobody → adapaka bhavaniprasad (adapaka-prasad) |
Changed in keystone: | |
assignee: | adapaka bhavaniprasad (adapaka-prasad) → nobody |
affects: | keystone → python-keystoneclient |
tags: |
added: security removed: python-keystoneclient |
Changed in ossa: | |
status: | Fix Committed → Fix Released |
Changed in python-keystoneclient: | |
milestone: | none → 0.2.4 |
status: | Fix Committed → Fix Released |
summary: |
[OSSA-2013-013] Updating password via keystoneclient CLI should be done - securely + securely (CVE-2013-2013) |
To post a comment you must log in.
adapaka - how are you doing on resolving this bug? Since you assigned it to yourself, I'm assuming you're trying to do that. If not, I'll move it back to unassigned.