Python package "zhmcclient" stores passwords in clear text in its HMC and API logs
Moderate severity
GitHub Reviewed
Published
Nov 28, 2024
in
zhmcclient/python-zhmcclient
•
Updated Dec 2, 2024
Description
Published by the National Vulnerability Database
Nov 29, 2024
Published to the GitHub Advisory Database
Dec 2, 2024
Reviewed
Dec 2, 2024
Last updated
Dec 2, 2024
Impact
The Python package "zhmcclient" writes password-like properties in clear text into its HMC and API logs in the following cases:
This issue affects only users of the zhmcclient package that have enabled the Python loggers named "zhmcclient.api" (for the API log) or "zhmcclient.hmc" (for the HMC log) and that use the functions listed above.
Patches
Has been fixed in zhmcclient version 1.18.1
Workarounds
Not applicable, since fix is available.
References
None
References