CVE-2014-7231
published 2014-10-08CVE-2014-7231: The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.53%
41.2th percentile
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-oslo.utils | < python-oslo.utils 0.2.0-1 (bookworm) | python-oslo.utils 0.2.0-1 (bookworm) |
| openstack | cinder | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | cinder | >= 2014.1 < 2014.1.3 | 2014.1.3 |
| openstack | nova | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | nova | >= 2014.1 < 2014.1.3 | 2014.1.3 |
| openstack | trove | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | trove | >= 2014.1 < 2014.1.3 | 2014.1.3 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Oslo utility sensitive information exposure via log files
ghsa·2022-05-14
CVE-2014-7231 [LOW] CWE-200 OpenStack Oslo utility sensitive information exposure via log files
OpenStack Oslo utility sensitive information exposure via log files
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
OSV
OpenStack Oslo utility sensitive information exposure via log files
osv·2022-05-14
CVE-2014-7231 [LOW] OpenStack Oslo utility sensitive information exposure via log files
OpenStack Oslo utility sensitive information exposure via log files
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
OSV
CVE-2014-7231: The strutils
osv·2014-10-08·CVSS 2.1
CVE-2014-7231 [LOW] CVE-2014-7231: The strutils
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
Red Hat
Trove: potential leak of passwords into log files
vendor_redhat·2014-07-22·CVSS 2.1
CVE-2014-7231 [LOW] CWE-184 Trove: potential leak of passwords into log files
Trove: potential leak of passwords into log files
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
Package: openstack-cinder (Red Hat OpenStack Platform 4) - Affected
Package: openstack-nova (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2014-7231: python-oslo.utils - The strutils.mask_password function in the OpenStack Oslo utility library, Cinde...
vendor_debian·2014·CVSS 2.1
CVE-2014-7231 [LOW] CVE-2014-7231: python-oslo.utils - The strutils.mask_password function in the OpenStack Oslo utility library, Cinde...
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
Scope: local
bookworm: resolved (fixed in 0.2.0-1)
bullseye: resolved (fixed in 0.2.0-1)
forky: resolved (fixed in 0.2.0-1)
sid: resolved (fixed in 0.2.0-1)
trixie: resolved (fixed in 0.2.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7230 CVE-2014-7231 openstack-nova: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
bugzilla·2014-10-09·CVSS 2.1
CVE-2014-7230 [LOW] CVE-2014-7230 CVE-2014-7231 openstack-nova: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
CVE-2014-7230 CVE-2014-7231 openstack-nova: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2014-7230 CVE-2014-7231 openstack-cinder: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
bugzilla·2014-10-09·CVSS 2.1
CVE-2014-7230 [LOW] CVE-2014-7230 CVE-2014-7231 openstack-cinder: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
CVE-2014-7230 CVE-2014-7231 openstack-cinder: OpenStack Cinder, Nova, Trove: potential leak of passwords into log files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2014-7230 CVE-2014-7231 OpenStack Cinder, Nova, Trove: potential leak of passwords into log files
bugzilla·2014-09-30·CVSS 2.1
CVE-2014-7230 [LOW] CVE-2014-7230 CVE-2014-7231 OpenStack Cinder, Nova, Trove: potential leak of passwords into log files
CVE-2014-7230 CVE-2014-7231 OpenStack Cinder, Nova, Trove: potential leak of passwords into log files
The OpenStack project reports:
""
Reporter: Amrith Kumar (Tesora)
Products: Cinder, Nova, Trove
Versions: up to 2013.2.3, 2014.1 versions up to 2014.1.2
Description:
Amrith Kumar from Tesora reported two vulnerabilities in the
processutils.execute() and strutils.mask_password() functions available
from oslo-incubator that are copied into each project's code. An
attacker with read access to the services' logs may obtain passwords
used as a parameter of a command that have failed or when the
mask_password did not mask passwords properly.
""
CVE request:
http://seclists.org/oss-sec/2014/q3/846
References:
https://launchpad.net/bugs/1343604
https://launchpad.net/bugs/1345233
Discussion:
http://rhn.redhat.com/errata/RHSA-2014-1939.htmlhttp://seclists.org/oss-sec/2014/q3/853http://www.securityfocus.com/bid/70184https://bugs.launchpad.net/oslo.utils/+bug/1345233https://exchange.xforce.ibmcloud.com/vulnerabilities/96726http://rhn.redhat.com/errata/RHSA-2014-1939.htmlhttp://seclists.org/oss-sec/2014/q3/853http://www.securityfocus.com/bid/70184https://bugs.launchpad.net/oslo.utils/+bug/1345233https://exchange.xforce.ibmcloud.com/vulnerabilities/96726
2014-10-08
Published