Bug 917802 (CVE-2015-3448) - VUL-1: CVE-2015-3448: rubygem-rest-client: Plaintext Password Local Disclosure
Summary: VUL-1: CVE-2015-3448: rubygem-rest-client: Plaintext Password Local Disclosure
Status: RESOLVED FIXED
Alias: CVE-2015-3448
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Bernhard Wiedemann
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/113876/
Whiteboard: CVSSv2:RedHat:CVE-2015-3448:2.1:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-02-13 12:12 UTC by Johannes Segitz
Modified: 2020-01-16 16:34 UTC (History)
8 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
reproducer (125 bytes, application/x-ruby)
2015-04-07 15:32 UTC, Jordi Massaguer
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2015-02-13 12:12:57 UTC
http://www.osvdb.org/show/osvdb/117461

REST Client for Ruby contains a flaw that is due to the application logging password information in plaintext. This may allow a local attacker to gain access to password information.

No CVE right now.
Comment 1 Swamp Workflow Management 2015-02-13 23:00:34 UTC
bugbot adjusting priority
Comment 7 Jordi Massaguer 2015-04-07 15:32:42 UTC
Created attachment 630237 [details]
reproducer

run this reproducer and, before the patch, you should get:

RestClient.get "https://user:password@...."

after the patch:

RestClient.get "https://user:REDACTER@..."
Comment 8 Bernhard Wiedemann 2015-04-07 16:00:06 UTC
This is an autogenerated message for OBS integration:
This bug (917802) was mentioned in
https://build.opensuse.org/request/show/294795 13.1 / rubygem-rest-client
Comment 10 Jordi Massaguer 2015-04-07 16:09:05 UTC
the fix is in 1.7.3 release

https://github.com/rest-client/rest-client/issues/349

thus no need to update devel:languages:ruby:extensions
Comment 11 Jordi Massaguer 2015-04-07 16:13:40 UTC
assigning it to security-team
Comment 12 Bernhard Wiedemann 2015-04-07 17:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (917802) was mentioned in
https://build.opensuse.org/request/show/294798 13.2 / rubygem-rest-client
Comment 13 Andreas Stieger 2015-04-08 11:18:31 UTC
(In reply to Bernhard Wiedemann from comment #12)
> This is an autogenerated message for OBS integration:
> This bug (917802) was mentioned in
> https://build.opensuse.org/request/show/294798 13.2 / rubygem-rest-client

This maintenance request has a review against devel:languages:ruby:extensions / rubygem-rest-client. Could you check this off please?
Comment 14 Jordi Massaguer 2015-04-08 14:33:28 UTC
request reviewed as I am maintainer in devel:languages:ruby:extensions
Comment 15 Swamp Workflow Management 2015-04-16 09:05:01 UTC
openSUSE-SU-2015:0724-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 917802
CVE References: 
Sources used:
openSUSE 13.2 (src):    rubygem-rest-client-1.6.7-7.3.1
openSUSE 13.1 (src):    rubygem-rest-client-1.6.7-4.3.1
Comment 22 Vincent Untz 2015-05-12 11:36:56 UTC
Bernhard: would you have time for these security updates? Or would you like someone else to help?
Comment 23 Vincent Untz 2015-10-23 11:34:02 UTC
The fix for this is in S:M:551.
Comment 24 Andreas Stieger 2016-01-08 12:30:02 UTC
Affects all openSUSE releases.
Affects, SLE-11-SP3-CL5, SLE-12 (SLE-12-CL5, SLE-12-SES2, SLE-12-SP1)

Please submit for SLE 11 as well.
Comment 29 Dirk Mueller 2019-07-22 14:55:09 UTC
looks like we never fixed this for cloud 7+
Comment 30 Dirk Mueller 2019-07-24 15:48:27 UTC
security-team, do we want to fix this for cloud?
Comment 32 Bernhard Wiedemann 2019-09-23 12:15:18 UTC
Added the fix to 
Devel:Cloud:Shared:Rubygem/rubygem-rest-client-1_6
so Rick will submit it as part of the next round of Maintenance Updates.
Comment 34 Swamp Workflow Management 2019-10-30 20:18:50 UTC
SUSE-SU-2019:2867-1: An update that solves 11 vulnerabilities and has 10 fixes is now available.

Category: security (moderate)
Bug References: 1019074,1096985,1106515,1115960,1116846,1118900,1120657,1125893,1126088,1132593,1132666,1136035,1141121,1141676,1143215,1145796,1146578,1148158,1148383,1150895,917802
CVE References: CVE-2015-3448,CVE-2016-10127,CVE-2018-15727,CVE-2018-19039,CVE-2018-558213,CVE-2019-13611,CVE-2019-15043,CVE-2019-2614,CVE-2019-2627,CVE-2019-2628,CVE-2019-5477
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    crowbar-core-5.0+git.1569597589.1f025c557-3.32.2, crowbar-ha-5.0+git.1567673535.607aada-3.26.2, crowbar-openstack-5.0+git.1570141351.058c8bd44-4.31.2, crowbar-ui-1.2.0+git.1568396400.0344a727-3.12.3, galera-3-25.3.25-4.6.3, grafana-4.6.5-4.6.3, mariadb-10.2.25-4.14.2, mariadb-connector-c-3.1.2-3.12.3, novnc-1.0.0-3.6.3, openstack-cinder-11.2.3~dev16-3.21.4, openstack-cinder-doc-11.2.3~dev16-3.21.3, openstack-glance-15.0.3~dev3-3.12.4, openstack-glance-doc-15.0.3~dev3-3.12.3, openstack-heat-9.0.8~dev13-3.24.4, openstack-heat-doc-9.0.8~dev13-3.24.3, openstack-horizon-plugin-neutron-vpnaas-ui-1.0.1~dev3-3.6.4, openstack-keystone-12.0.4~dev4-5.27.4, openstack-keystone-doc-12.0.4~dev4-5.27.3, openstack-monasca-installer-20190923_16.32-3.9.3, openstack-neutron-11.0.9~dev51-3.24.5, openstack-neutron-doc-11.0.9~dev51-3.24.4, openstack-neutron-gbp-7.3.1~dev56-3.9.4, openstack-neutron-lbaas-11.0.4~dev6-3.15.4, openstack-neutron-lbaas-doc-11.0.4~dev6-3.15.4, openstack-nova-16.1.9~dev7-3.29.3, openstack-nova-doc-16.1.9~dev7-3.29.3, python-amqp-2.2.2-3.6.3, python-ovs-2.7.2-3.6.1, python-pysaml2-4.0.2-5.3.3, python-urllib3-1.22-5.9.3, release-notes-suse-openstack-cloud-8.20190911-3.20.3, rubygem-easy_diff-1.0.0-3.4.2
SUSE OpenStack Cloud 8 (src):    ardana-ansible-8.0+git.1566374355.c509923-3.67.3, ardana-glance-8.0+git.1566376789.be0fe01-3.17.3, ardana-horizon-8.0+git.1565816064.5d4f73f-3.18.3, ardana-input-model-8.0+git.1566517401.98450e6-3.33.3, ardana-manila-8.0+git.1568835837.2452e7a-1.21.3, ardana-neutron-8.0+git.1568220097.74ee4b4-3.33.3, ardana-nova-8.0+git.1566902754.c58ff69-3.35.3, ardana-octavia-8.0+git.1568373448.bcaee7e-3.20.3, ardana-tempest-8.0+git.1566471887.fd2fec7-3.27.3, galera-3-25.3.25-4.6.3, grafana-4.6.5-4.6.3, mariadb-10.2.25-4.14.2, mariadb-connector-c-3.1.2-3.12.3, novnc-1.0.0-3.6.3, openstack-cinder-11.2.3~dev16-3.21.4, openstack-cinder-doc-11.2.3~dev16-3.21.3, openstack-glance-15.0.3~dev3-3.12.4, openstack-glance-doc-15.0.3~dev3-3.12.3, openstack-heat-9.0.8~dev13-3.24.4, openstack-heat-doc-9.0.8~dev13-3.24.3, openstack-horizon-plugin-neutron-vpnaas-ui-1.0.1~dev3-3.6.4, openstack-keystone-12.0.4~dev4-5.27.4, openstack-keystone-doc-12.0.4~dev4-5.27.3, openstack-monasca-installer-20190923_16.32-3.9.3, openstack-neutron-11.0.9~dev51-3.24.5, openstack-neutron-doc-11.0.9~dev51-3.24.4, openstack-neutron-gbp-7.3.1~dev56-3.9.4, openstack-neutron-lbaas-11.0.4~dev6-3.15.4, openstack-neutron-lbaas-doc-11.0.4~dev6-3.15.4, openstack-nova-16.1.9~dev7-3.29.3, openstack-nova-doc-16.1.9~dev7-3.29.3, python-amqp-2.2.2-3.6.3, python-ovs-2.7.2-3.6.1, python-pysaml2-4.0.2-5.3.3, python-python-engineio-2.0.2-3.3.3, python-urllib3-1.22-5.9.3, release-notes-suse-openstack-cloud-8.20190911-3.20.3, venv-openstack-aodh-5.1.1~dev7-12.20.2, venv-openstack-barbican-5.0.2~dev3-12.21.2, venv-openstack-ceilometer-9.0.8~dev7-12.18.2, venv-openstack-cinder-11.2.3~dev16-14.21.2, venv-openstack-designate-5.0.3~dev7-12.19.2, venv-openstack-freezer-5.0.0.0~xrc2~dev2-10.16.2, venv-openstack-glance-15.0.3~dev3-12.19.2, venv-openstack-heat-9.0.8~dev13-12.21.2, venv-openstack-horizon-12.0.4~dev6-14.26.2, venv-openstack-ironic-9.1.8~dev7-12.21.2, venv-openstack-keystone-12.0.4~dev4-11.22.3, venv-openstack-magnum-5.0.2_5.0.2_5.0.2~dev31-11.20.2, venv-openstack-manila-5.1.1~dev2-12.23.2, venv-openstack-monasca-2.2.2~dev1-11.18.2, venv-openstack-monasca-ceilometer-1.5.1_1.5.1_1.5.1~dev3-8.16.2, venv-openstack-murano-4.0.2~dev2-12.16.2, venv-openstack-neutron-11.0.9~dev51-13.24.3, venv-openstack-nova-16.1.9~dev7-11.22.3, venv-openstack-octavia-1.0.6~dev2-12.21.2, venv-openstack-sahara-7.0.4~dev1-11.20.2, venv-openstack-swift-2.15.2-11.13.3, venv-openstack-trove-8.0.1~dev13-11.20.2
HPE Helion Openstack 8 (src):    ardana-ansible-8.0+git.1566374355.c509923-3.67.3, ardana-glance-8.0+git.1566376789.be0fe01-3.17.3, ardana-horizon-8.0+git.1565816064.5d4f73f-3.18.3, ardana-input-model-8.0+git.1566517401.98450e6-3.33.3, ardana-manila-8.0+git.1568835837.2452e7a-1.21.3, ardana-neutron-8.0+git.1568220097.74ee4b4-3.33.3, ardana-nova-8.0+git.1566902754.c58ff69-3.35.3, ardana-octavia-8.0+git.1568373448.bcaee7e-3.20.3, ardana-tempest-8.0+git.1566471887.fd2fec7-3.27.3, galera-3-25.3.25-4.6.3, grafana-4.6.5-4.6.3, mariadb-10.2.25-4.14.2, mariadb-connector-c-3.1.2-3.12.3, novnc-1.0.0-3.6.3, openstack-cinder-11.2.3~dev16-3.21.4, openstack-cinder-doc-11.2.3~dev16-3.21.3, openstack-glance-15.0.3~dev3-3.12.4, openstack-glance-doc-15.0.3~dev3-3.12.3, openstack-heat-9.0.8~dev13-3.24.4, openstack-heat-doc-9.0.8~dev13-3.24.3, openstack-horizon-plugin-neutron-vpnaas-ui-1.0.1~dev3-3.6.4, openstack-keystone-12.0.4~dev4-5.27.4, openstack-keystone-doc-12.0.4~dev4-5.27.3, openstack-monasca-installer-20190923_16.32-3.9.3, openstack-neutron-11.0.9~dev51-3.24.5, openstack-neutron-doc-11.0.9~dev51-3.24.4, openstack-neutron-gbp-7.3.1~dev56-3.9.4, openstack-neutron-lbaas-11.0.4~dev6-3.15.4, openstack-neutron-lbaas-doc-11.0.4~dev6-3.15.4, openstack-nova-16.1.9~dev7-3.29.3, openstack-nova-doc-16.1.9~dev7-3.29.3, python-amqp-2.2.2-3.6.3, python-pysaml2-4.0.2-5.3.3, python-python-engineio-2.0.2-3.3.3, python-urllib3-1.22-5.9.3, release-notes-hpe-helion-openstack-8.20190911-3.20.3, venv-openstack-aodh-5.1.1~dev7-12.20.2, venv-openstack-barbican-5.0.2~dev3-12.21.2, venv-openstack-ceilometer-9.0.8~dev7-12.18.2, venv-openstack-cinder-11.2.3~dev16-14.21.2, venv-openstack-designate-5.0.3~dev7-12.19.2, venv-openstack-freezer-5.0.0.0~xrc2~dev2-10.16.2, venv-openstack-glance-15.0.3~dev3-12.19.2, venv-openstack-heat-9.0.8~dev13-12.21.2, venv-openstack-horizon-hpe-12.0.4~dev6-14.26.2, venv-openstack-ironic-9.1.8~dev7-12.21.2, venv-openstack-keystone-12.0.4~dev4-11.22.3, venv-openstack-magnum-5.0.2_5.0.2_5.0.2~dev31-11.20.2, venv-openstack-manila-5.1.1~dev2-12.23.2, venv-openstack-monasca-2.2.2~dev1-11.18.2, venv-openstack-monasca-ceilometer-1.5.1_1.5.1_1.5.1~dev3-8.16.2, venv-openstack-murano-4.0.2~dev2-12.16.2, venv-openstack-neutron-11.0.9~dev51-13.24.3, venv-openstack-nova-16.1.9~dev7-11.22.3, venv-openstack-octavia-1.0.6~dev2-12.21.2, venv-openstack-sahara-7.0.4~dev1-11.20.2, venv-openstack-swift-2.15.2-11.13.3, venv-openstack-trove-8.0.1~dev13-11.20.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 35 Bernhard Wiedemann 2019-11-18 10:35:48 UTC
Fixed for SOC8.
Probably still open for SOC7.
Comment 37 Swamp Workflow Management 2020-01-13 14:13:57 UTC
SUSE-SU-2020:0081-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1157028,1157482,1158675,917802
CVE References: CVE-2015-3448,CVE-2019-13117,CVE-2019-16770
Sources used:
SUSE OpenStack Cloud 7 (src):    crowbar-core-4.0+git.1574788924.e4a6aeb0c-9.60.2, crowbar-openstack-4.0+git.1574869671.9c7bade2d-9.65.1, openstack-horizon-plugin-monasca-ui-1.5.5~dev3-8.1, openstack-monasca-api-1.7.1~dev18-12.1, openstack-monasca-log-api-1.4.3~dev3-5.1, openstack-neutron-9.4.2~dev21-7.38.1, openstack-neutron-doc-9.4.2~dev21-7.38.1, rubygem-puma-2.16.0-4.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 38 Wolfgang Frisch 2020-01-16 16:34:36 UTC
All code streams appear to be fixed.