CVE-2021-3585 describes a flaw in openstack-tripleo-heat-templates where plain text RHSM passwords are logged during OpenStack Platform 13 deployments using subscription-manager. This vulnerability is rated Medium (CVSS 5.5) due to its local attack vector and low complexity, potentially leading to high confidentiality impact if logs are accessed. While no active exploitation, public exploit code, or significant community discussion has been observed, the exposure of sensitive credentials remains a concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.4.1CPE matchmatch criteria | cpe:2.3:a:openstack:tripleo_heat_templates:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.