CVE-2014-7231

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2014-1939.html Third Party Advisory
http://seclists.org/oss-sec/2014/q3/853 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/70184 Third Party Advisory VDB Entry
https://bugs.launchpad.net/oslo.utils/+bug/1345233 Exploit Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/96726 Third Party Advisory VDB Entry
http://rhn.redhat.com/errata/RHSA-2014-1939.html Third Party Advisory
http://seclists.org/oss-sec/2014/q3/853 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/70184 Third Party Advisory VDB Entry
https://bugs.launchpad.net/oslo.utils/+bug/1345233 Exploit Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/96726 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:trove:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:trove:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:openstack:5.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:16

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2014-1939.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-1939.html - Third Party Advisory
References () http://seclists.org/oss-sec/2014/q3/853 - Mailing List, Third Party Advisory () http://seclists.org/oss-sec/2014/q3/853 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/70184 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/70184 - Third Party Advisory, VDB Entry
References () https://bugs.launchpad.net/oslo.utils/+bug/1345233 - Exploit, Third Party Advisory () https://bugs.launchpad.net/oslo.utils/+bug/1345233 - Exploit, Third Party Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/96726 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/96726 - Third Party Advisory, VDB Entry

Information

Published : 2014-10-08 19:55

Updated : 2024-11-21 02:16


NVD link : CVE-2014-7231

Mitre link : CVE-2014-7231

CVE.ORG link : CVE-2014-7231


JSON object : View

Products Affected

openstack

  • trove
  • cinder
  • nova

redhat

  • openstack
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor