Skip to content

OpenStack Oslo utility sensitive information exposure via log files

Low severity GitHub Reviewed Published May 14, 2022 to the GitHub Advisory Database • Updated May 14, 2024

Package

pip oslo.utils (pip)

Affected versions

< 0.2.0

Patched versions

0.2.0

Description

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

References

Published by the National Vulnerability Database Oct 8, 2014
Published to the GitHub Advisory Database May 14, 2022
Reviewed May 14, 2024
Last updated May 14, 2024

Severity

Low

Weaknesses

CVE ID

CVE-2014-7231

GHSA ID

GHSA-v933-vx5p-j7w2

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.