{"id":"CVE-2015-3646","aliases":["GHSA-jwpw-ppj5-7h4w","PYSEC-2026-655"],"title":"OpenStack Keystone Logs Passwords","summary":"OpenStack Keystone Logs Passwords","severity":"medium","vendor":"keystone","product":"keystone","ecosystem":"pip","affected":["keystone >= 2011.3, < 2014.1.5","keystone >= 2014.2, < 2014.2.4"],"patched":["keystone 2014.1.5","keystone 2014.2.4"],"published":"2022-05-13","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jwpw-ppj5-7h4w","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3646"},{"url":"https://bugs.launchpad.net/keystone/+bug/1443598"},{"url":"https://github.com/openstack/keystone"},{"url":"https://web.archive.org/web/20210122154200/http://www.securityfocus.com/bid/74456"},{"url":"http://lists.openstack.org/pipermail/openstack-announce/2015-May/000356.html"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html"}],"tags":["osv","pip"],"epss":0.0288,"epssPercentile":0.86177,"ingestedAt":"2026-07-08T18:25:50.895Z","slug":"CVE-2015-3646","body":"## Overview\n\nOpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.\n\n## Affected packages\n\n- `keystone >= 2011.3, < 2014.1.5`\n- `keystone >= 2014.2, < 2014.2.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `keystone 2014.1.5`\n- `keystone 2014.2.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.6,"exploitation":0,"ransomware":0},"changes":[]}