CVE-2022-3261 is a high-severity information disclosure vulnerability affecting Red Hat OpenStack Platform. It allows plain-text passwords to be logged in /var/log/messages during overcloud updates, exposing sensitive credentials. With a CVSS score of 7.5, this network-exploitable flaw requires no user interaction and could lead to significant data compromise. While no public exploits, Metasploit modules, or active exploitation have been observed, and community discussion is minimal, organizations using affected OpenStack versions should prioritize remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.2CPE matchmatch criteria | cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.