Password Logging Flaw in OpenStack Oslo Utility Library Products
CVE-2014-7231

Currently unrated

Key Information:

Vendor
Openstack
Vendor
CVE Published:
8 October 2014

Summary

The strutils.mask_password function in the OpenStack Oslo utility library inadvertently reveals sensitive passwords in logged command outputs. This issue exists in Cinder, Nova, and Trove prior to the specified versions, enabling unauthorized local users to read these logs and potentially gain access to confidential information. Proper password masking is therefore critical to safeguard user credentials and maintain system integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.