CVE-2014-7230
published 2014-10-08CVE-2014-7230: The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.47%
37.9th percentile
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | cinder | < cinder 2014.1.3-4 (bookworm) | cinder 2014.1.3-4 (bookworm) |
| debian | nova | < cinder 2014.1.3-4 (bookworm) | cinder 2014.1.3-4 (bookworm) |
| debian | openstack-trove | < cinder 2014.1.3-4 (bookworm) | cinder 2014.1.3-4 (bookworm) |
| openstack | cinder | >= 0 < 2014.1.3-4 | 2014.1.3-4 |
| openstack | cinder | >= 0 < 2014.1.3-4 | 2014.1.3-4 |
| openstack | cinder | >= 0 < 2014.1.3-4 | 2014.1.3-4 |
| openstack | cinder | >= 0 < 2014.1.3-4 | 2014.1.3-4 |
| openstack | cinder | >= 0 < 1:2014.1.3-0ubuntu1.1 | 1:2014.1.3-0ubuntu1.1 |
| openstack | cinder | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | cinder | >= 2014.1 < 2014.1.3 | 2014.1.3 |
| openstack | nova | >= 0 < 2014.1.3-5 | 2014.1.3-5 |
| openstack | nova | >= 0 < 2014.1.3-5 | 2014.1.3-5 |
| openstack | nova | >= 0 < 2014.1.3-5 | 2014.1.3-5 |
| openstack | nova | >= 0 < 2014.1.3-5 | 2014.1.3-5 |
| openstack | nova | >= 0 < 1:2014.1.3-0ubuntu1.1 | 1:2014.1.3-0ubuntu1.1 |
| openstack | nova | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | nova | >= 2014.1 < 2014.1.3 | 2014.1.3 |
| openstack | trove | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | trove | >= 2014.1 < 2014.1.3 | 2014.1.3 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.0MEDIUM
vendor_ubuntu4.0MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-58w7-wcrr-7289: The processutils
ghsa_unreviewed·2022-05-14
CVE-2014-7230 [LOW] CWE-200 GHSA-58w7-wcrr-7289: The processutils
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
OSV
nova vulnerabilities
osv·2014-11-11·CVSS 2.7
CVE-2014-3608 [LOW] nova vulnerabilities
nova vulnerabilities
Garth Mollett discovered that OpenStack Nova did not properly clean up an
instance when using rescue mode with the VMWare driver. A remove
authenticated user could exploit this to bypass intended quota limits. By
default, Ubuntu does not use the VMWare driver. (CVE-2014-3608)
Amrith Kumar discovered that OpenStack Nova did not properly sanitize log
message contents. Under certain circumstances, a local attacker with read
access to Nova log files could obtain access to sensitive information.
(CVE-2014-7230)
OSV
cinder vulnerabilities
osv·2014-11-11·CVSS 4.0
CVE-2014-3641 [MEDIUM] cinder vulnerabilities
cinder vulnerabilities
Duncan Thomas discovered that OpenStack Cinder did not properly track the
file format when using the GlusterFS of Smbfs drivers. A remote
authenticated user could exploit this to potentially obtain file contents
from the compute host. (CVE-2014-3641)
Amrith Kumar discovered that OpenStack Cinder did not properly sanitize log
message contents. Under certain circumstances, a local attacker with read
access to Cinder log files could obtain access to sensitive information.
(CVE-2014-7230)
OSV
CVE-2014-7230: The processutils
osv·2014-10-08·CVSS 2.1
CVE-2014-7230 [LOW] CVE-2014-7230: The processutils
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Ubuntu
OpenStack Cinder vulnerabilities
vendor_ubuntu·2014-11-11·CVSS 4.0
CVE-2014-3641 [MEDIUM] OpenStack Cinder vulnerabilities
Title: OpenStack Cinder vulnerabilities
Summary: OpenStack Cinder could be made to expose sensitive information over the
network.
Duncan Thomas discovered that OpenStack Cinder did not properly track the
file format when using the GlusterFS of Smbfs drivers. A remote
authenticated user could exploit this to potentially obtain file contents
from the compute host. (CVE-2014-3641)
Amrith Kumar discovered that OpenStack Cinder did not properly sanitize log
message contents. Under certain circumstances, a local attacker with read
access to Cinder log files could obtain access to sensitive information.
(CVE-2014-7230)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
OpenStack Nova vulnerabilities
vendor_ubuntu·2014-11-11·CVSS 2.7
CVE-2014-3608 [LOW] OpenStack Nova vulnerabilities
Title: OpenStack Nova vulnerabilities
Summary: OpenStack Nova could be made to expose sensitive information.
Garth Mollett discovered that OpenStack Nova did not properly clean up an
instance when using rescue mode with the VMWare driver. A remove
authenticated user could exploit this to bypass intended quota limits. By
default, Ubuntu does not use the VMWare driver. (CVE-2014-3608)
Amrith Kumar discovered that OpenStack Nova did not properly sanitize log
message contents. Under certain circumstances, a local attacker with read
access to Nova log files could obtain access to sensitive information.
(CVE-2014-7230)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Trove: potential leak of passwords into log files
vendor_redhat·2014-07-22·CVSS 2.1
CVE-2014-7230 [LOW] CWE-184 Trove: potential leak of passwords into log files
Trove: potential leak of passwords into log files
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Package: openstack-cinder (Red Hat OpenStack Platform 4) - Affected
Package: openstack-nova (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2014-7230: cinder - The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and...
vendor_debian·2014·CVSS 2.1
CVE-2014-7230 [LOW] CVE-2014-7230: cinder - The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and...
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Scope: local
bookworm: resolved (fixed in 2014.1.3-4)
bullseye: resolved (fixed in 2014.1.3-4)
forky: resolved (fixed in 2014.1.3-4)
sid: resolved (fixed in 2014.1.3-4)
trixie: resolved (fixed in 2014.1.3-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7230 CVE-2014-7231 openstack-nova: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
bugzilla·2014-10-09·CVSS 2.1
CVE-2014-7230 [LOW] CVE-2014-7230 CVE-2014-7231 openstack-nova: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
CVE-2014-7230 CVE-2014-7231 openstack-nova: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2014-7230 CVE-2014-7231 openstack-cinder: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
bugzilla·2014-10-09·CVSS 2.1
CVE-2014-7230 [LOW] CVE-2014-7230 CVE-2014-7231 openstack-cinder: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
CVE-2014-7230 CVE-2014-7231 openstack-cinder: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2014-7230 CVE-2014-7231 OpenStack Cinder, Nova, Trove: potential leak of passwords into log files
bugzilla·2014-09-30·CVSS 2.1
CVE-2014-7230 [LOW] CVE-2014-7230 CVE-2014-7231 OpenStack Cinder, Nova, Trove: potential leak of passwords into log files
CVE-2014-7230 CVE-2014-7231 OpenStack Cinder, Nova, Trove: potential leak of passwords into log files
The OpenStack project reports:
""
Reporter: Amrith Kumar (Tesora)
Products: Cinder, Nova, Trove
Versions: up to 2013.2.3, 2014.1 versions up to 2014.1.2
Description:
Amrith Kumar from Tesora reported two vulnerabilities in the
processutils.execute() and strutils.mask_password() functions available
from oslo-incubator that are copied into each project's code. An
attacker with read access to the services' logs may obtain passwords
used as a parameter of a command that have failed or when the
mask_password did not mask passwords properly.
""
CVE request:
http://seclists.org/oss-sec/2014/q3/846
References:
https://launchpad.net/bugs/1343604
https://launchpad.net/bugs/1345233
Discussion:
http://rhn.redhat.com/errata/RHSA-2014-1939.htmlhttp://seclists.org/oss-sec/2014/q3/853http://www.securityfocus.com/bid/70185http://www.ubuntu.com/usn/USN-2405-1https://bugs.launchpad.net/oslo-incubator/+bug/1343604https://exchange.xforce.ibmcloud.com/vulnerabilities/96725http://rhn.redhat.com/errata/RHSA-2014-1939.htmlhttp://seclists.org/oss-sec/2014/q3/853http://www.securityfocus.com/bid/70185http://www.ubuntu.com/usn/USN-2405-1https://bugs.launchpad.net/oslo-incubator/+bug/1343604https://exchange.xforce.ibmcloud.com/vulnerabilities/96725
2014-10-08
Published