Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7231

Опубликовано: 22 июл. 2014
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 4openstack-cinderAffected
Red Hat OpenStack Platform 4openstack-novaAffected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-novaFixedRHSA-2014:178103.11.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-cinderFixedRHSA-2014:178703.11.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-novaFixedRHSA-2014:178203.11.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-cinderFixedRHSA-2014:178803.11.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-troveFixedRHSA-2014:193902.12.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-184
Дефект:
CWE-532->CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1147722Trove: potential leak of passwords into log files

EPSS

Процентиль: 37%
0.00157
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

nvd
больше 11 лет назад

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

debian
больше 11 лет назад

The strutils.mask_password function in the OpenStack Oslo utility libr ...

github
больше 3 лет назад

OpenStack Oslo utility sensitive information exposure via log files

EPSS

Процентиль: 37%
0.00157
Низкий

2.1 Low

CVSS2