[OSSA-2013-013] Updating password via keystoneclient CLI should be done securely (CVE-2013-2013)
Bug #938315 reported by
Jake Dahn
This bug affects 2 people
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| OpenStack Security Advisory |
Fix Released
|
Low
|
Jeremy Stanley | ||
| python-keystoneclient |
Fix Released
|
High
|
Pradeep Kilambi | ||
Bug Description
Updating password via CLI should be done via a secure password prompt, not text.
current: keystone user-password-
expected: keystone user-password-
CVE References
| tags: | added: python-keystoneclient |
| Changed in keystone: | |
| assignee: | nobody → Brian Waldon (bcwaldon) |
| Changed in keystone: | |
| status: | New → In Progress |
| Changed in keystone: | |
| status: | In Progress → Triaged |
| assignee: | Brian Waldon (bcwaldon) → nobody |
| Changed in keystone: | |
| assignee: | nobody → adapaka bhavaniprasad (adapaka-prasad) |
| assignee: | adapaka bhavaniprasad (adapaka-prasad) → nobody |
| Changed in keystone: | |
| assignee: | nobody → adapaka bhavaniprasad (adapaka-prasad) |
| Changed in keystone: | |
| assignee: | adapaka bhavaniprasad (adapaka-prasad) → nobody |
| affects: | keystone → python-keystoneclient |
| tags: |
added: security removed: python-keystoneclient |
| Changed in ossa: | |
| status: | Fix Committed → Fix Released |
| Changed in python-keystoneclient: | |
| milestone: | none → 0.2.4 |
| status: | Fix Committed → Fix Released |
| summary: |
[OSSA-2013-013] Updating password via keystoneclient CLI should be done - securely + securely (CVE-2013-2013) |
To post a comment you must log in.

adapaka - how are you doing on resolving this bug? Since you assigned it to yourself, I'm assuming you're trying to do that. If not, I'll move it back to unassigned.