CVE-2024-41129
ops: Insertion of Sensitive Information into Log File (CVE-2024-41129)
mediumEPSS 0.2%
Affected
- pypi/ops
2.0.0..* - pypi/ops
2.1.0..* - pypi/ops
2.1.1..* - pypi/ops
2.10.0..* - pypi/ops
2.11.0..* - pypi/ops
2.12.0..* - pypi/ops
2.13.0..* - pypi/ops
2.14.0..* - pypi/ops
2.14.1..* - pypi/ops
2.2.0..* - pypi/ops
2.3.0..* - pypi/ops
2.4.0..* - pypi/ops
2.4.1..* - pypi/ops
2.5.0..* - pypi/ops
2.5.1..* - pypi/ops
2.6.0..* - pypi/ops
2.7.0..* - pypi/ops
2.8.0..* - pypi/ops
2.9.0..*
Description
The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing `subprocess.CalledProcessError`. This vulnerability is fixed in 2.15.0.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
pypiops
2.0.02.1.02.10.02.1.12.11.02.12.02.13.02.14.02.14.12.2.02.3.02.4.02.4.12.5.02.5.12.6.02.7.02.8.02.9.0Metrics
Show all metrics
Severity
medium
44.24
no public PoC known
4.4
Published
2026-07-07 14:34 UTC
CWE-532
Weakness classes (CWE)
CWE-532Base
Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
cwe.mitre.org →