Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. zhmcclient
  4. ›
  5. CVE-2024-53865

CVE-2024-53865: Python package "zhmcclient" stores passwords in clear text in its HMC and API logs

December 2, 2024

The Python package “zhmcclient” writes password-like properties in clear text into its HMC and API logs in the following cases:

  • The ‘boot-ftp-password’ and ‘ssc-master-pw’ properties when creating or updating a partition in DPM mode, in the zhmcclient API and HMC logs
  • The ‘ssc-master-pw’ and ‘zaware-master-pw’ properties when updating an LPAR in classic mode, in the zhmcclient API and HMC logs
  • The ‘ssc-master-pw’ and ‘zaware-master-pw’ properties when creating or updating an image activation profile in classic mode, in the zhmcclient API and HMC logs
  • The ‘password’ property when creating or updating an HMC user, in the zhmcclient API log
  • The ‘bind-password’ property when creating or updating an LDAP server definition, in the zhmcclient API and HMC logs

This issue affects only users of the zhmcclient package that have enabled the Python loggers named “zhmcclient.api” (for the API log) or “zhmcclient.hmc” (for the HMC log) and that use the functions listed above.

References

  • github.com/advisories/GHSA-p57h-3cmc-xpjq
  • github.com/zhmcclient/python-zhmcclient
  • github.com/zhmcclient/python-zhmcclient/commit/ad32781e782d0f604c6da4680fce48e4cc1f4433
  • github.com/zhmcclient/python-zhmcclient/security/advisories/GHSA-p57h-3cmc-xpjq
  • nvd.nist.gov/vuln/detail/CVE-2024-53865

Code Behaviors & Features

Detect and mitigate CVE-2024-53865 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.18.1

Fixed versions

  • 1.18.1

Solution

Upgrade to version 1.18.1 or above.

Impact 8.2 HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-312: Cleartext Storage of Sensitive Information

Source file

pypi/zhmcclient/CVE-2024-53865.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:32 +0000.