Description
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-7102 | The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log. |
Ubuntu USN |
USN-2405-1 | OpenStack Cinder vulnerabilities |
Ubuntu USN |
USN-2407-1 | OpenStack Nova vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T12:40:19.269Z
Reserved: 2014-09-29T00:00:00.000Z
Link: CVE-2014-7230
No data.
Status : Modified
Published: 2014-10-08T19:55:04.453
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-7230
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN