PT-2014-7847 · Openstack · Nova+3

Amrith

+1

·

Published

2014-10-08

·

Updated

2022-05-14

·

CVE-2014-7231

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Oslo utility library versions prior to 2013.2.4 OpenStack Oslo utility library versions prior to 2014.1.3 Cinder versions prior to 2013.2.4 Cinder versions prior to 2014.1.3 Nova versions prior to 2013.2.4 Nova versions prior to 2014.1.3 Trove versions prior to 2013.2.4 Trove versions prior to 2014.1.3
Description The issue is related to the strutils.mask password function, which does not properly mask passwords when logging commands. This allows local users to obtain passwords by reading the log.
Recommendations For OpenStack Oslo utility library versions prior to 2013.2.4, update to version 2013.2.4 or later. For OpenStack Oslo utility library versions prior to 2014.1.3, update to version 2014.1.3 or later. For Cinder versions prior to 2013.2.4, update to version 2013.2.4 or later. For Cinder versions prior to 2014.1.3, update to version 2014.1.3 or later. For Nova versions prior to 2013.2.4, update to version 2013.2.4 or later. For Nova versions prior to 2014.1.3, update to version 2014.1.3 or later. For Trove versions prior to 2013.2.4, update to version 2013.2.4 or later. For Trove versions prior to 2014.1.3, update to version 2014.1.3 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7231
GHSA-V933-VX5P-J7W2
RHSA-2014:1781
RHSA-2014:1782
RHSA-2014:1787
RHSA-2014:1788
RHSA-2014:1939
SUSE-SU-2015:0324-1

Affected Products

Cinder
Nova
Openstack Oslo Utility Library
Trove