CVE-2014-7231

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2014-1939.html Third Party Advisory
http://seclists.org/oss-sec/2014/q3/853 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/70184 Third Party Advisory VDB Entry
https://bugs.launchpad.net/oslo.utils/+bug/1345233 Exploit Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/96726 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:trove:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:trove:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:openstack:5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-10-08 19:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-7231

Mitre link : CVE-2014-7231

CVE.ORG link : CVE-2014-7231


JSON object : View

Products Affected

openstack

  • cinder
  • nova
  • trove

redhat

  • openstack
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor