CVE-2014-7231
Last modified
CVE-2014-7231 is a vulnerability of currently unknown severity. The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Cinder | >= 2013.2, < 2013.2.4 |
| Openstack | Cinder | >= 2014.1, < 2014.1.3 |
| Openstack | Nova | >= 2013.2, < 2013.2.4 |
| Openstack | Nova | >= 2014.1, < 2014.1.3 |
| Openstack | Trove | >= 2013.2, < 2013.2.4 |
| Openstack | Trove | >= 2014.1, < 2014.1.3 |
| Redhat | Openstack | 5.0 |
References
- http://rhn.redhat.com/errata/RHSA-2014-1939.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q3/853Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/70184Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/oslo.utils/+bug/1345233Exploit, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96726Third Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2014-1939.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q3/853Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/70184Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/oslo.utils/+bug/1345233Exploit, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96726Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7231?
How severe is CVE-2014-7231?
How do I fix CVE-2014-7231?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-7224A Code Execution vulnerability exists in Android prior to 4.…8.8
- CVE-2014-7226The file comment feature in Rejetto HTTP File Server (hfs) 2…
- CVE-2014-7227Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2014-7228Akeeba Restore (restore.php), as used in Joomla! 2.5.4 throu…
- CVE-2014-7229Unspecified vulnerability in Joomla! before 2.5.4 before 2.5…
- CVE-2014-7230The processutils.execute function in OpenStack oslo-incubato…
- CVE-2014-7232GE Healthcare Discovery XR656 and XR656 G2 has a password of…
- CVE-2014-7233GE Healthcare Precision THUNIS-800+ has a default password o…
- CVE-2014-7234Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-7235htdocs_ari/includes/login.php in the ARI Framework module/As…
- CVE-2014-7236Eval injection vulnerability in lib/TWiki/Plugins.pm in TWik…9.1
- CVE-2014-7237lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when runnin…
Are you affected by CVE-2014-7231?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
