Password Logging Flaw in OpenStack Oslo Utility Library Products
CVE-2014-7231
Currently unrated
Summary
The strutils.mask_password function in the OpenStack Oslo utility library inadvertently reveals sensitive passwords in logged command outputs. This issue exists in Cinder, Nova, and Trove prior to the specified versions, enabling unauthorized local users to read these logs and potentially gain access to confidential information. Proper password masking is therefore critical to safeguard user credentials and maintain system integrity.
References
Timeline
Vulnerability published
Vulnerability Reserved