-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| oslo-utils | pip | < 4.10.1 | 4.10.1 |
The vulnerability stemmed from improper regex handling in the password masking logic. The commit 6e17ae1f7959c64dfd20a5f67edf422e702426aa explicitly modifies the regex patterns and adds new wildcard patterns (_FORMAT_PATTERNS_WILDCARD) in strutils.py to address quote handling. Test cases in test_strutils.py demonstrate scenarios where passwords with quotes were previously partially exposed. The mask_password function is directly responsible for credential obfuscation in logs, making it the clear vulnerable component.
KEV Misses 88% of Exploited CVEs- Get the report