CVE-2014-7231

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
References
Link Resource
http://www.securityfocus.com/bid/70184 Third Party Advisory VDB Entry
http://seclists.org/oss-sec/2014/q3/853 Mailing List Third Party Advisory
https://bugs.launchpad.net/oslo.utils/+bug/1345233 Exploit Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1939.html Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/96726 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:trove:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:trove:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:openstack:5.0:*:*:*:*:*:*:*

Information

Published : 2014-10-08 12:55

Updated : 2018-11-16 07:28


NVD link : CVE-2014-7231

Mitre link : CVE-2014-7231


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

openstack

  • trove
  • nova
  • cinder

redhat

  • openstack