*SECRETS LEAK* on paste.openstack.org

Bug #1913326 reported by Monty Taylor
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Core Infrastructure
Fix Released
Critical
Jeremy Stanley

Bug Description

as a result of leaks of passwords, tokens, keys and configuration from https://paste.openstack.org/raw/244916, many confidential data from developers, cloud environments, CI / CD systems may fall into the wrong hands.
There is over 801 000 files, many of them contains secrets - already changed credentials of openstack project administrator - Monty Taylor is example (sorry man, and respect for your work)I am asking for quick reactions to protect your data and systems.

I kindly ask you to support and donate the charity foundation SpartanieDzieciom.org - good returns - <email address hidden>

https://imgur.com/gallery/sCEg6df

https://fb.com/SpartanieDzieciom

Revision history for this message
Monty Taylor (mordred) wrote :
information type: Private Security → Public
Monty Taylor (mordred)
Changed in ossa:
status: New → Confirmed
assignee: nobody → Monty Taylor (mordred)
Monty Taylor (mordred)
information type: Public → Public Security
Jeremy Stanley (fungi)
affects: ossa → openstack-ci
Revision history for this message
Jeremy Stanley (fungi) wrote :

Closing this for now, it was a specific incident and the affected user was aware. In the near future we plan to modify https://opendev.org/opendev/lodgeit/src/branch/master/lodgeit/views/new_paste.html to invert or remove the "paste private" option so that nondeterministic URLs are used by default.

Changed in openstack-ci:
assignee: Monty Taylor (mordred) → Jeremy Stanley (fungi)
importance: Undecided → Critical
affects: openstack-ci → openstack-dev-sandbox
Changed in openstack-dev-sandbox:
status: Confirmed → Fix Released
affects: openstack-dev-sandbox → openstack-ci
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.