CVE-2014-7230: Infoleak
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7230?
CVE-2014-7230 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2014-7230?
To fix CVE-2014-7230, update OpenStack components Cinder, Nova, and Trove to versions 2013.2.4 or 2014.1.3 or later.
What does CVE-2014-7230 exploit?
CVE-2014-7230 exploits the processutils.execute function to allow local users to read sensitive information from logs.
Which OpenStack components are affected by CVE-2014-7230?
CVE-2014-7230 affects OpenStack components Cinder, Nova, and Trove prior to specific patched versions.
Can CVE-2014-7230 impact my system's security?
Yes, CVE-2014-7230 can impact system security by allowing local users to access credentials through error logs.