Vulnerability Description
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Cinder | >= 2013.2, < 2013.2.4 |
| Openstack | Nova | >= 2013.2, < 2013.2.4 |
| Openstack | Trove | >= 2013.2, < 2013.2.4 |
| Redhat | Openstack | 5.0 |
| Canonical | Ubuntu Linux | 14.04 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2014-1939.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q3/853Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/70185Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2405-1Third Party Advisory
- https://bugs.launchpad.net/oslo-incubator/+bug/1343604Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96725Third Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2014-1939.htmlThird Party Advisory
- http://seclists.org/oss-sec/2014/q3/853Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/70185Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2405-1Third Party Advisory
- https://bugs.launchpad.net/oslo-incubator/+bug/1343604Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96725Third Party AdvisoryVDB Entry
FAQ
What is CVE-2014-7230?
CVE-2014-7230 is a vulnerability with a CVSS score of 2.1 (LOW). The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a Proc...
How severe is CVE-2014-7230?
CVE-2014-7230 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-7230?
Check the references section above for vendor advisories and patch information. Affected products include: Openstack Cinder, Openstack Nova, Openstack Trove, Redhat Openstack, Canonical Ubuntu Linux.