Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-7231

Опубликовано: 08 окт. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1

Описание

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

РелизСтатусПримечание
devel

not-affected

1.0.0-0ubuntu1
esm-infra-legacy/trusty

DNE

lucid

DNE

precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

0.2.0

Показывать по

EPSS

Процентиль: 37%
0.00157
Низкий

2.1 Low

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

nvd
больше 11 лет назад

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

debian
больше 11 лет назад

The strutils.mask_password function in the OpenStack Oslo utility libr ...

github
больше 3 лет назад

OpenStack Oslo utility sensitive information exposure via log files

EPSS

Процентиль: 37%
0.00157
Низкий

2.1 Low

CVSS2