CVE-2024-41129

ops: Insertion of Sensitive Information into Log File (CVE-2024-41129)

mediumEPSS 0.2%

Affected

  • pypi/ops 2.0.0..*
  • pypi/ops 2.1.0..*
  • pypi/ops 2.1.1..*
  • pypi/ops 2.10.0..*
  • pypi/ops 2.11.0..*
  • pypi/ops 2.12.0..*
  • pypi/ops 2.13.0..*
  • pypi/ops 2.14.0..*
  • pypi/ops 2.14.1..*
  • pypi/ops 2.2.0..*
  • pypi/ops 2.3.0..*
  • pypi/ops 2.4.0..*
  • pypi/ops 2.4.1..*
  • pypi/ops 2.5.0..*
  • pypi/ops 2.5.1..*
  • pypi/ops 2.6.0..*
  • pypi/ops 2.7.0..*
  • pypi/ops 2.8.0..*
  • pypi/ops 2.9.0..*

Description

The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing `subprocess.CalledProcessError`. This vulnerability is fixed in 2.15.0.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

pypiops
2.0.02.1.02.10.02.1.12.11.02.12.02.13.02.14.02.14.12.2.02.3.02.4.02.4.12.5.02.5.12.6.02.7.02.8.02.9.0

Metrics

4.4
Source: cna-v3
8.9 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-07 14:34 UTC
CWE-532

Weakness classes (CWE)

  • CWE-532Base

    Insertion of Sensitive Information into Log File

    The product writes sensitive information to a log file.

    cwe.mitre.org →

References & sources